Security & Trust

Security enforced at every layer.

Every decision and audit record is tamper-evident and independently re-verifiable, API access is least-privilege and scoped, outbound events are signed and SSRF-hardened, and every change is gated on a passing safety-guard suite. Security is enforced in code and CI — and the platform has no capital-movement path to begin with.

AI analyzes. Deterministic systems validate. Humans authorize. Capital remains governed.

At a glance
Decision & audit recordsTamper-evident
API keysLeast-privilege
TransportTLS + HSTS + CSP
Capital movementNo code path
How we secure the platform

The controls that run today.

Concrete, verifiable controls in place across records, access, delivery, change management, and the software supply chain — each stated as what it does, not what it aspires to.

Tamper-evident records
In place
append-only + re-verify

Decision and audit records are append-only with a per-record provenance hash, enforced at the database layer. A recompute-on-read verify endpoint lets a reviewer re-check integrity independently — evidence you can audit, not just trust.

Least-privilege API access
In place
scoped + hashed

Restricted, workspace-scoped API keys confine a key to a route allow-set. Keys are stored as one-way hashes, shown once at creation, and compared in constant time.

Signed, SSRF-hardened webhooks
In place
off by default

Outbound events are HMAC-signed and delivered through an SSRF-hardened gate: private, loopback, and metadata-address ranges are refused and DNS-rebinding is re-checked at send time. Delivery stays off until explicitly enabled.

Gated change management
In place
enforced on main

The protected main branch requires review and passing continuous-integration checks — including an automated safety-guard suite — before any change can merge. Security posture is enforced in code and CI, not documented after the fact.

Supply-chain & code scanning
In place
reviewed deps + CI guards

Dependency updates flow through reviewed pull requests, and an architecture- and safety-guard test suite runs on every merge to main. A static-analysis (SAST) pipeline (CodeQL) is configured and pending activation — we do not represent it as running until it is.

Hardened transport & disclosure
In place
TLS + HSTS + CSP

Public traffic is TLS-encrypted with strict transport-security and content-security policies, and a published vulnerability-disclosure policy (security.txt, RFC 9116) is served on every host.

Capital risk, designed out

The strongest control is a capability you never expose.

SigmaX prepares evidence and decision records — it has no path to turn them into capital movement. Removing that capability removes an entire class of breach: there is nothing to compromise, misconfigure, or exfiltrate into a transfer.

No capital-movement path

No broker, custody, transfer, allocation, or customer-capital routing surface exists in the product. The class of breach that moves money is designed out, not merely disabled.

AI proposes, humans authorize

AI, Atlas, the website, and the client portal produce evidence, proof gaps, approval state, and route state. They cannot authorize a capital-linked action — a human is always the authorization layer.

Operator-owned credentials

Provider credentials are operator-owned and never exposed on public surfaces, which reference env-var names and readiness — never secret values.

Labeled evidence, never upgraded

Sample, demo, paper, and real evidence stay labeled at every layer. Sample data cannot become real customer evidence by presentation alone.

Every review recorded

Impact Ledger and AuditWriter preserve who reviewed what, which evidence existed, and what route state was produced — a reconstructable trail for any diligence request.

Live rails are counsel-gated

Any future live-execution or customer-capital route is gated behind separate legal review and explicit operator approval before it can exist.

Attestations & status

Status stated exactly — never implied.

In-product evidence lineage is available to review today. Formal third-party attestation is a separate line — we state its status precisely and never imply coverage we do not have.

Impact Ledger + Audit
In place
available - read-only

Decision and evidence lineage can be assembled for any review as part of the Capital Action OS workflow. These records inform decisions; they do not grant execution authority.

Sample-data handling
In place
labeled

Demo outputs, simulations, and sample packets stay visibly labeled and cannot become real customer evidence by presentation alone.

SOC 2 & penetration test
In progress
in progress - not yet claimed

We do not represent SOC 2 or an external penetration test as finished. When an artifact exists, this page will state its exact status or link the report — nothing sooner.

Subprocessor register
In progress
on request

A formal public subprocessor register is not yet published. Current subprocessors can be shared under a diligence review rather than implied as a complete list.

Offer alignment

Security posture by access path.

View pricing ->

Builder Sandbox

Sample or paper only

Learns the ActionIntent lifecycle without live authority, live customer capital, or external execution.

Authority Team and Institutional OS

Controlled access

Supports governed review records, required-approver state, mandate checks, route status, and audit output.

ActionIntent API

Scoped, no execution surface

Returns decision-check results and references through least-privilege scoped keys — without becoming a broker, custodian, transfer system, or order router.

Private Infrastructure and Pilot

Reviewed engagement

Scopes private controls, evidence posture, and implementation requirements before any production deployment.

Compliance disclaimer

SigmaX provides capital decision intelligence, scenario analysis, and authority workflow software. SigmaX does not provide investment advice. SigmaX does not place trades, move funds, route customer capital, or manage client capital. Shadow/simulated/paper/backtested results are not live trading results. No result is a guarantee of future performance. Human approval is required before any capital-linked action.

Where SigmaX uses AI, it is governed as assistive software: truthful capability claims, human oversight, traceable records, disclosure of AI assistance, and no capital authority. SigmaX designs AI controls with reference to applicable securities obligations, FINRA existing-rule guidance, SEC AI-claims discipline, NIST AI RMF-style risk management, and EU AI Act transparency readiness. This is compliance-readiness design, not a claim that every deployment or jurisdiction-specific use has completed legal review.

Start your security review here.

Access reviews and diligence start from verifiable records, least-privilege scoped access, and an architecture with no capital-movement path. Ask for the detail your team needs.