Founding-partner program now open · start a scoped proof →

Trust & compliance

Built for environments that cannot afford to guess.

This page covers our compliance posture, data handling, encryption model, subprocessors, and responsible disclosure — written for procurement teams, security reviewers, and InfoSec leads doing real due diligence.

What data we handle

Your identity data stays in your environment.

→ What stays in your environment

  • Identity event payloads (who, what, when)
  • Pre-state and post-state of target systems
  • Evidence packs (written to your own S3 bucket)
  • Encryption keys (BYO-KMS, customer-held)
  • All connector credentials and API tokens

What reaches the SidantiX control plane

  • Policy evaluation requests (anonymized by default)
  • Connector health telemetry
  • Execution status signals
No raw identity data, by default configuration.
Encryption & key ownership

The proof is yours — cryptographically.

In transit

Mutual TLS (mTLS) on all connector traffic. Certificate pinning available for regulated deployments.

At rest

Evidence packs signed with ECDSA P-256, hash-chained with SHA-256. S3 Object Lock in Compliance Mode.

Key ownership

BYO-KMS: you supply and rotate your own KMS key. SidantiX cannot read evidence without your key access.

Compliance posture

Honest status. No green-check theater.

FrameworkStatusNotes
SOC 2 Type IIIn preparationControls designed to SOC 2 Trust Service Criteria. Formal audit engagement planned Q3 2026.
FedRAMPInformed, not authorizedArchitecture informed by FedRAMP moderate control families. Not authorized; independent review required for FedRAMP-in-scope workloads.
NIST 800-53 Rev.5Designed-toAC, AU, IA, and SI control families inform product design. Formal control mapping in progress; not independently assessed.
HIPAAAlignedDeployment patterns support HIPAA-aligned environments. BAA terms available for qualified deployments under signed agreement.
OWASP ASIAlignedAI-agent governance controls aligned to the OWASP Agentic Security Initiative guidelines.
Compliance references describe alignment and readiness, not certification, unless stated in a signed customer artifact.
Subprocessors

A short, honest list.

ProcessorPurposeData involved
Amazon Web ServicesControl-plane hosting, evidence storageCustomer-defined; evidence packs in customer-owned S3
CloudflareCDN and DDoS protection for public sitePublic web traffic only — no identity data
Responsible disclosure

Found something? Tell us.

If you discover a security issue, email [email protected] with a description, reproduction steps, and your contact details. We acknowledge within 2 business days and respond substantively within 10. Please allow reasonable time to investigate before public disclosure.

Evidence retention is customer-controlled. SidantiX does not set or enforce retention periods — you configure S3 Object Lock and bucket lifecycle policies in your own AWS account.
What we don't have yet

Honest gaps — so you know what to ask for.

DocumentStatusNotes
Pentest reportNot yetThird-party pentest planned alongside SOC 2 engagement. Contact us for timeline.
CAIQ / SIG questionnaireNot yetHappy to complete a SIG Lite or CAIQ v4 for qualified evaluations under NDA.
Sample DPA / BAANot yetTemplate DPA and BAA in legal review. Available on request for design-partner engagements.
Certificate of insuranceNot yetCyber liability and E&O coverage being finalized. COI available on request once bound.
If your procurement process requires any of these, contact us — we'll tell you honestly where we are and when we expect to have it.
What happens if SidantiX disappears

Your evidence survives us.

Every evidence pack is signed with your tenant's own key, stored in your S3 bucket with Object Lock retention you control. The verification CLI is open-source — it checks signatures against your public key, not ours. If SidantiX ceases to operate tomorrow, every receipt you've collected remains independently verifiable on an air-gapped laptop with no SidantiX infrastructure involved. Your keys, your storage, your proof.

Legal entity

Who you're contracting with.

SidantiX, Inc. — incorporated in the State of California. Principal office: Sacramento, CA. For legal correspondence: [email protected].

Doing a security review?

We're happy to walk your team through the architecture, share control documentation, and discuss NDA evaluation terms.