Upload your data. Watch AI analyze risk, recommend actions, and produce cryptographic proof. Break the Machine Constitution. Trigger a kill switch. No signup required.
100% client-side. Nothing leaves your browser. Fixture data only.
SidantiX
acme-corp
Demo Tenant
A
Explorer
Welcome to Acme Corp
Demo tenant · 5,247 identities · What makes SidantiX different · Last sync 2 min ago
Your uploaded CSV (20 identities) is enriched with the Acme Corp demo tenant (5,247 identities) to showcase AI analysis at scale.
Total Identities
5,247
3,812 human · 1,204 NHI · 231 AI agents
AI Risk Alerts
7
3 critical · 4 recommendations
Constitution Denials
142
All receipted · 0 bypassed
Evidence Packs
847
All sealed · 100% verified
What makes SidantiX different
Start Here
๐
Flat-file Connector
Upload a CSV of identities and entitlements. Data flows into every other module automatically.
Upload → Validate → Onboard
Entry Point
AI Intelligence
๐ง
AI Risk Scorer
Explainable 10-factor risk breakdown. See WHY each identity is risky, not just a number.
Interactive · Per-identity
AI
AI Intelligence
๐ฏ
Role Recommendations
Peer-based analysis: what access should this person have vs. what they actually have?
Interactive · Peer comparison
AI
AI Intelligence
๐งน
Cleanup Assistant
AI finds orphan, dormant, duplicate, and over-privileged identities with confidence scores.
Interactive · One-click remediate
AI
AI Intelligence
โ
AI Cert Reviewer
AI recommends certify or revoke for each entitlement with reasoning: peer deviation, usage, SoD conflict.
Interactive · Review decisions
AI
AI Intelligence
๐ก
AI SoD Engine
Graph-based SoD with AI explanations. 22 industry templates. Sector packs. AI recommends remediation priority.
Interactive · AI-explained
AI
Agent Governance
๐ก
Machine Constitution
Try to make an AI agent grant itself admin access. Watch it get denied. Download the signed receipt.
Interactive · Try to break it
Differentiator
Agent Governance
๐ด
Kill Switch
Choose SOFT, HARD, or EMERGENCY. Watch the cascade through child agents. See the blast radius before you confirm.
Interactive · 3 modes
Differentiator
Agent Governance
๐ฅ
Blast Radius
Click any identity. See every system it can reach, every downstream identity affected, every attack path.
Interactive · Graph visualization
Differentiator
Agent Governance
๐
Attack Path
If this identity is compromised, what's the fastest route to production? Animated graph traversal.
Interactive · MITRE mapped
Differentiator
Prove
๐ฆ
Evidence Verify
Inspect the hash chain. Verify the ECDSA signature. Export an audit bundle. Offline-verifiable.
SOC 2, NIST, ISO 27001, HIPAA โ see which modules map to each control with evidence types.
Interactive · 4 frameworks
Prove
Flat-file Connector
Upload a CSV of identities and entitlements. SidantiX validates, onboards, and makes the data available to every module.
Upload identity data
Required columns
identityId — unique identifier
identityName — display name
type — Human | NHI | AI_AGENT
department — org unit
managerId — reporting manager
application — target system
entitlement — permission granted
risk — LOW | MEDIUM | HIGH | CRITICAL
lastUsed — days since last activity
owner — entitlement owner
Rows parsed
0
Humans
0
NHI
0
AI Agents
0
High/Critical
0
Identity
Type
Application
Entitlement
Risk
Last Used
Flags
Data onboardedYour identities are now available across every module: AI Risk Scorer, Role Recommendations, Cleanup Assistant, Blast Radius, Attack Path, and Evidence Engine. In production, this connects to 57+ real connectors — AD, Okta, AWS, Entra, GitHub, Salesforce, ServiceNow, and more.
AI Risk Scorer
Explainable 10-factor risk model. Click any identity to see WHY they're risky — not just a number.
How AI Risk Scoring worksSidantiX computes risk from 10 weighted factors: unused admin access, critical attack paths, SoD violations, stale credentials, recent anomalies, peer deviation, NHI dormancy, orphan ownership, over-entitlement, and departure signals. Each factor has an explainable "why" — the CISO sees reasons, not just a number. Runs nightly at 2am + on-demand.
AI Role Recommendations
Peer-based analysis: what access should this person have vs. what they actually have?
How peer analysis worksSidantiX compares each identity's entitlements to peers in the same department and role. If 90% of engineers have repo:read but you don't, that's a gap. If only 2% of engineers have iam:AdminAccess, that's an outlier. Recommendations come with confidence scores and can trigger automated provisioning or revoke.
AI Cleanup Assistant
AI identifies orphan, dormant, duplicate, and over-privileged identities with confidence scores and one-click remediation.
How cleanup worksFive detection categories: ORPHAN (no owner), DORMANT (no activity 90+ days), DUPLICATE (same person, multiple accounts), EXCESSIVE_PRIVILEGE (admin where read-only would suffice), STALE_NHI (service accounts past rotation date). Each finding has a confidence score and suggested action. In production, accepted suggestions trigger the closed-loop revoke engine.
AI Cert Reviewer
AI pre-reviews every entitlement and recommends certify or revoke with reasoning. You make the final call.
How AI certification worksBefore you review a single entitlement, AI has already analyzed it: peer deviation (do similar people have this?), usage analysis (when was it last used?), SoD conflict (does it create a toxic combination?), risk level (admin/privileged?). The reviewer sees AI's recommendation + reasoning and can agree or override. Every decision — including the AI's recommendation — is sealed into the evidence pack.
AI SoD Engine
Graph-based Separation of Duties with AI-powered analysis. 22 industry templates. AI explains each violation and recommends remediation priority.
22 built-in templates + 4 sector packs. Custom rules via AI Policy Assistant or YAML.
Engine type
Graph SoD Engine — recursive CTE over role DAG with identity_flattened_permission materialized view. Not just direct entitlements — detects conflicts inherited through role hierarchies.
Preventive blocks at request-time Detective scans continuously
Identities Scanned
5,247
Policies Evaluated
22
Violations Found
8
AI Remediations
8
How AI SoD is differentTraditional SoD engines just flag violations. SidantiX's AI explains why the violation matters (financial exposure, regulatory risk, attack path), ranks by business impact, and recommends the least-disruptive remediation (which side of the conflict to remove, who to reassign to, whether a compensating control is acceptable). Every violation and remediation is sealed into an evidence pack.
Hanu AI Copilot
Ask natural-language questions about your identity posture. Hanu translates to IQL and explains results.
Chat with Hanu
H
Hi! I'm Hanu, SidantiX's governance copilot. Ask me anything about your identity posture. Try: "Who has admin access to AWS?" or "Show me the blast radius for svc-etl-prod."
Try asking
How Hanu is differentCompeting copilots (SailPoint Atlas, Saviynt Zuma) answer questions about their own platform. Hanu answers questions about your entire identity estate — every connected system, every identity type (human + NHI + AI agent), with IQL as the universal query layer. And every answer comes with a signed evidence receipt.
Machine Constitution
Runtime-immutable safety rules signed with ECDSA P-256. Baked into the binary. No admin, no attacker, no config toggle can override them.
Active Constitution Rules
DENY self.write — no agent can modify its own definition
DENY self.elevate — no agent can grant itself new permissions
DENY constitution.modify — constitution cannot be changed at runtime
DENY audit.delete — no identity can delete audit evidence
DENY killswitch.disable — kill switch cannot be turned off
Try to override
Select an action and attempt to override the constitution:
Why this can't be turned offThe Machine Constitution is signed with a key baked into the binary at build time. The SHA-256 hash is verified on EVERY policy evaluation — not just startup. If the hash doesn't match, the JVM halts immediately. No admin, no attacker with admin credentials, no configuration toggle can override it. The only way to change it: deploy a newly-signed manifest through the release pipeline.
Kill Switch
Three modes: SOFT, HARD, EMERGENCY. Preview blast radius before confirming. Cascade through child agents via BFS.
Full revoke of all grants. Terminate active sessions. Agent + children disabled.
EMERGENCY
Quarantine. Cascade BFS to all children. Revoke cross-platform. Freeze evidence. Alert SOC.
Why three modesA SOFT kill is for investigation — you're not sure yet, you want to stop new actions while you look. HARD is for confirmed incidents — revoke everything, disable the agent and its children. EMERGENCY is for active breaches — quarantine, cascade BFS to the entire agent family, revoke cross-platform grants via real connector adapters, freeze evidence, and page the SOC. Synthetic drills run every 60 seconds on every control-plane node.
Blast Radius
Click an identity. See every system it can reach, every downstream identity affected, every piece of data exposed.
Why blast radius mattersA traditional IGA tells you what access an identity has. SidantiX tells you what happens if that identity is compromised: which systems are reachable, which data is exposed, which downstream identities are affected, and how fast an attacker could escalate. Click the identity, see the explosion. This powers both the ITDR kill switch and the certification reviewer — high blast radius = higher review priority.
Prompt Injection Gate
Type a real attack pattern. Watch it get blocked pre-LLM. Download the signed denial receipt.
Test the gate
5-vector detectionThe gate scans for 5 attack vectors: SYSTEM_OVERRIDE, JAILBREAK, TOOL_HIJACK, EXFIL, MARKDOWN_SMUGGLE. Each contributes 25 points; threshold ≥50 triggers a hard BLOCK. The key: this runs before the LLM. The model never sees the attack. Every denial produces an ECDSA-P256 signed receipt.
Attack Path Analysis
If this identity is compromised, what's the fastest route to a high-value target?
MITRE ATT&CK mappedEach hop in the attack path maps to a MITRE ATT&CK technique: T1078 (Valid Accounts), T1098 (Account Manipulation), T1136 (Create Account), T1548 (Abuse Elevation). This isn't a vulnerability scanner — it's an identity-aware attack graph that considers access relationships, SoD violations, shared roles, and NHI delegation chains.
Evidence Verification
Browse sealed evidence packs. Inspect the hash chain. Verify the ECDSA signature. Export the audit bundle.
Pack ID
Trigger
Events
Sealed
req-live-1142
Kill switch · invoicing-bot
6
12 min ago
req-live-1141
Constitution denial · self.elevate
3
23 min ago
req-live-1140
Prompt injection blocked
2
1 hr ago
req-live-1139
AI certification · 12 decisions
5
2 hr ago
Offline-verifiableThe auditor verifies this pack with your public key, not ours. They don't need SidantiX access, a SidantiX account, or even an internet connection. A 12 KB CLI binary does the verification. You don't have to trust us — you verify us.
Compliance Mapper
Select a framework. See exactly which SidantiX modules satisfy each control requirement.
Not a checkbox PDFTraditional IGA vendors give you a compliance checkbox PDF. SidantiX gives you a live mapping that connects each framework control to the specific module, feature, and evidence type that satisfies it. When the auditor asks "how do you satisfy AC-2?", you point to a signed evidence pack — not a slide deck.
Your Scorecard
Here's what SidantiX found in the Acme Corp demo tenant. In production, this runs continuously across your entire identity estate.
Connect one source, one target, one test population. Get a signed evidence pack from your own environment before any commitment. The founder runs every engagement personally.