Sigmix Zero · sovereign endpoint

The whole sovereign workspace, on one Windows 11 device.

Sigmix Zero is our own Windows 11 hardware — a sealed, on-device AI workstation that runs the full Sigmix suite locally. Zero cloud, zero outbound connections, for the most sensitive desks in the Kingdom.

// on-device models · zero outbound connections · Sigmix Guard inside

Sigmix Zero — the sovereign AI workstation Sigmix Zero · Windows 11 · on-device
The rack's posture, on a desk
On-device models Default-deny networking Sigmix Guard inside DigiCert code-signed Arabic + English
What makes it Zero

Nothing to call home to.

Most "secure AI" laptops are ordinary machines with a policy attached. Zero is built the other way round: the models are already on the device, so there is nothing the network needs to carry.

On-device models

Chat, documents, images and code run on local models — your data never leaves the machine, because the model is already sitting on it.

Zero outbound connections

Default-deny networking with a live On-Premise Mode indicator on screen — the same posture as the rack, on a desk.

Sigmix Guard inside

The scrubbing and audit-anchor layer runs on the endpoint too, so PII is redacted before it ever touches a document. How Guard works →

The device

The full suite, running on the machine in front of you.

Not a thin client, not a remote session. These are the real screens, rendering locally with the network off.

Sigmix Zero — the device AI chat running on-device The Sigmix tool grid on Sigmix Zero The code assistant in Arabic on Sigmix Zero Sigmix Zero in full right-to-left Arabic The device · sealed & offline
Where it goes

The desks that can't use the cloud.

Legal, HR, board and ministry desks where the document on screen is the reason the cloud was never an option.

Sigmix Zero on a desk
A sealed workstation, on an ordinary desk.
Sigmix Zero in an executive office in Riyadh
Executive and board desks in the Kingdom.
Sigmix Zero driving dual monitors
Drives your existing monitors and peripherals.
Two ways to run it

A sealed machine, or a portable folder.

Zero ships as our own Windows 11 hardware for the most sensitive desks. For teams that already have locked-down machines, the same suite runs as a portable folder — copy and run, no installer and no network — so a sealed environment can be served without new procurement.

DigiCert code-signed installersigned · verifiable · silent install
The two Sigmix Zero editions Sealed device · portable edition
Native Windows software · for cyber & IT

Deploy it the way your IT already works.

Sigmix Zero and the Sigmix workspace ship as native Windows software your team pushes through its existing tooling — no new agents, no exceptions to your baseline. Silent install, managed mode, and fully sealed operation are all covered.

Cloud / MDM path

Microsoft Intune

Push the .intunewin package to managed endpoints straight from the cloud.

SCCM / MECM · on-prem

Configuration Manager

On-prem software distribution through your existing MECM infrastructure.

MSI + ADMX policy

Group Policy (GPO)

MSI deployment plus an ADMX / registry policy template for locked-down managed mode.

WiX MSI or NSIS

The installer

A signed WiX .msi (silent install) or an NSIS setup.exe — pushed by any channel above.

Portable · copy-and-run

Sealed / USB

The portable Sigmix Zero folder — copy and run, no installer and no network, for sealed environments.

// silent install · managed mode via ADMX/registry · your existing tooling · zero new agents

Sigmix Zero running in full right-to-left Arabic Full right-to-left · عربي
Bilingual · عربي

Arabic on the device, not via a server.

The whole interface mirrors to full right-to-left, and the Arabic output is generated by an Arabic-first model rather than translated. Because the model is local, that holds with the network unplugged — which is the point of the machine.

Questions

For IT, security and procurement

Does it work with no network at all?
Yes. The models run on the device, so chat, documents, images and code all work with the machine fully disconnected. Networking is default-deny, and an On-Premise Mode indicator on screen tells the user which state they are in.
Is it as capable as the rack?
No, and we would rather say so. A desk-sized machine reaches lower model tiers than a GPU rack — that is physics, not policy. Everyday chat, documents, drafting and coding run well on-device; the heaviest reasoning wants the appliance or the in-Kingdom cloud. The capability table shows exactly what runs where.
Do we have to buy your hardware?
Not necessarily. Zero ships as our own sealed Windows 11 hardware, but the same suite also runs as a portable copy-and-run folder on machines you already control — useful when procurement is slower than the requirement.
How do we deploy it across a fleet?
Through the tooling you already run — Intune, SCCM/MECM, or Group Policy with an ADMX template for managed mode. The installer is a signed WiX MSI supporting silent install. No new management agent is introduced.
How are models updated on a sealed machine?
Deliberately, by your team, from verified media — the same principle as the appliance. Nothing self-updates over a network that is not supposed to exist.
Is the installer signed?
Yes — DigiCert code-signed, so your endpoint protection and application-control policies can verify it before it runs.
Next step

Put one on a desk.

The fastest way to judge Zero is to unplug it. Request a unit, hand it to the team with the most sensitive documents in the building, and see what they can do with the network off.

Need this for a whole department rather than a desk? Sovereign AI Servers run the same suite from your own rack.