Security & trust
Built for outbound-only, air-gap-adjacent networks — no inbound ports, customer-held keys, and evidence you can verify offline without trusting us. Here's exactly how.
Three decisions made on day one that you can't bolt on later.
A customer-managed gateway dials out over mutual TLS. No inbound ports, no VPN, no firewall exceptions. For restricted, on-premises, and high-compliance environments, deployment is scoped around your approved outbound paths during the proof.
Evidence is hash-chained, signed, and written to storage you own — your S3 bucket, your Object Lock, your retention. We never hold the only copy, and you can verify the chain entirely offline.
The connector requests the minimum scopes it needs, per system, and every action it takes is itself logged into the same tamper-evident chain. The tool that governs access is held to the same standard.
SidantiX orchestrates and proves — it doesn't become a new copy of your identity data to worry about.
Evidence is sealed at the gateway and lands in your own bucket. Nothing about the design requires you to trust SidantiX as the custodian of record — the proof is yours, and it's verifiable without us.
AI agents governed by SidantiX don't just follow policy — every action is egress-controlled, constitution-attested, time-bounded, red-team-tested, and kill-switch-guaranteed.
Every AI agent declares which external systems it may call. The outbound gateway enforces the allowlist — a rogue or injected agent physically cannot reach an undeclared endpoint. Blocked calls produce a signed denial receipt.
The Machine Constitution's SHA-256 hash is verified against the boot-attested value on every single policy evaluation — not just at startup. If the hash doesn't match, the JVM halts immediately. No silent drift.
Every permission grant to an AI agent carries a mandatory expiry (default 24h, max 90 days). Expired grants are refused at evaluation time — no more "forgotten" AI permissions accumulating silently.
Every release is tested against 200+ known AI attack patterns — prompt injection, constitution bypass, self-elevation, tool escape — seeded from OWASP LLM Top 10. A regression blocks the build from shipping.
A synthetic kill-switch drill runs every 60 seconds on every control-plane node. Three consecutive SLO breaches and the node automatically drains itself — you can shut down any AI agent in under one second, guaranteed.
These aren't roadmap promises — the design docs are written, the API contracts are defined, and each one ships as an independently verifiable module. Ask us to walk through any of them.
We're an early-stage company and we won't claim certifications we don't have. Here's the real status — and the architecture is designed to map cleanly onto each framework.
Status reflects current readiness, not formal attestation unless stated. We'll share our architecture and control mappings with prospective founding partners under NDA.
We'd rather have the deep architecture conversation early. Founding partners get our full control mappings and a hands-on technical review.