Security & Trust

Security enforced at every layer.

Every decision and audit record is tamper-evident and independently re-verifiable, API access is least-privilege and scoped, outbound events are signed and SSRF-hardened, and every change runs an automated safety-guard suite in CI. Security is engineered into code and CI - and the platform exposes no customer-facing capital-movement path in this release.

AI analyzes. Deterministic systems validate. Humans authorize. Capital remains governed.

At a glance
Decision & audit recordsTamper-evident
API keysLeast-privilege
TransportTLS + HSTS + CSP
Capital movementNo customer path
How we secure the platform

Where each control acts.

Seven controls, placed where they run. One is not in place — it is on the map anyway.

Your systems
agents · portfolio system · research
API gateway
the boundary every call crosses
SigmaX
decision + audit records
Signed webhooks
outbound events
Your review UI
committee · risk · audit
Every hop above rides TLS + HSTS + CSP · security.txt on every host
Engineering & supply chain
how a change reaches production
Capital movement
broker · custody · transfer · allocation · customer-capital routing
NO CUSTOMER PATH
2IN PLACE

Tamper-evident records

append-only + re-verify

Decision and audit records are append-only with a per-record provenance hash, enforced at the database layer. A recompute-on-read verify endpoint lets a reviewer re-check integrity independently — evidence you can audit, not just trust.

click a numbered marker · statuses stated exactly — nothing implied

Capital risk, designed out

The strongest control is a capability you never expose.

SigmaX prepares evidence and decision records. The enabled product exposes no customer-facing path to turn them into capital movement. Future live-capital pathways remain outside this release and require separate legal review, operator approval, and certified execution controls before they can exist.

No customer capital-movement path

No customer-facing broker, custody, transfer, allocation, or customer-capital routing surface exists in this product release. Capital movement remains outside the enabled product boundary.

AI proposes, humans authorize

AI, Atlas, the website, and the client portal produce evidence, proof gaps, approval state, and route state. They cannot authorize a capital-linked action — a human is always the authorization layer.

Operator-owned credentials

Provider credentials are operator-owned and never exposed on public surfaces, which reference env-var names and readiness — never secret values.

Labeled evidence, never upgraded

Sample, demo, paper, and real evidence stay labeled at every layer. Sample data cannot become real customer evidence by presentation alone.

Every review recorded

Impact Ledger and AuditWriter preserve who reviewed what, which evidence existed, and what route state was produced — a reconstructable trail for any diligence request.

Live rails are counsel-gated

Any future live-execution or customer-capital route is gated behind separate legal review and explicit operator approval before it can exist.

Attestations & status

Status stated exactly — never implied.

In-product evidence lineage is available to review today. Formal third-party attestation is a separate line — we state its status precisely and never imply coverage we do not have.

Impact Ledger + Audit
In place
available - read-only

Decision and evidence lineage can be assembled for any review as part of the Capital Action OS workflow. These records inform decisions; they do not grant execution authority.

Sample-data handling
In place
labeled

Demo outputs, simulations, and sample packets stay visibly labeled and cannot become real customer evidence by presentation alone.

SOC 2 & penetration test
Planned
planned - not yet started

A SOC 2 engagement has not started, and no external penetration test has been performed. Both are planned. When an engagement produces an artifact, this page will state its exact status or link the report — nothing sooner.

Subprocessor register
Planned
on request

A formal public subprocessor register is not yet published. Current subprocessors can be shared under a diligence review rather than implied as a complete list.

Diligence bundle

The Assurance Pack, line by line — including the lines we cannot yet fill.

This is the full contents of the security bundle a reviewer receives, with the exact status of each item. We publish the incomplete lines deliberately: a pack that hides its gaps is not evidence.

9 of 18 items available today

Independent testing and formal attestation are scoped but not yet executed. When an engagement produces an artifact, this list will change — and not before.

  • Security architecture overviewIn place
  • Data-flow and trust-boundary diagramPlanned
  • Agent threat modelPlanned
  • Access-control modelIn place
  • Tenant-isolation designIn place
  • Encryption and key-management summaryIn place
  • Independent penetration-test attestationPlanned
  • Remediation letterPlanned
  • Incident-response procedurePlanned
  • Disaster-recovery restoration test resultPlanned
  • Subprocessor listPlanned
  • Data-retention and deletion policyIn place
  • Model and agent change-management policyPlanned
  • Sample ActionIntentIn place
  • Sample Decision RecordIn place
  • Audit replay demonstrationIn place
  • Control mapping to your own frameworkPlanned
  • Explicit no-custody / no-execution boundary statementIn place
Intellectual property

A patent-pending evidence-governance architecture.

The controls above are not only enforced — the architecture behind them is proprietary. SigmaX's fail-closed candidate-promotion gate and related evidence-governance design are the subject of seven U.S. provisional patent applications filed with the United States Patent and Trademark Office, covering six distinct inventions.

“Patent pending” means an application has been filed with the USPTO — not a representation that any patent has been granted or will be granted. Named filings are set out in our disclosures.

Read the intellectual-property disclosures ->
At a glance
Filings7 U.S. provisional
StatusPatent pending
CoversEvidence governance
DetailSee /disclosures
Offer alignment

Security posture by access path.

View pricing ->

Builder Sandbox

Sample or paper only

Learns the ActionIntent lifecycle without live authority, live customer capital, or external execution.

Authority Team and Institutional OS

Controlled access

Supports governed review records, required-approver state, mandate checks, route status, and audit output.

ActionIntent API

Scoped, no execution surface

Returns decision-check results and references through least-privilege scoped keys — without becoming a broker, custodian, transfer system, or order router.

Private Infrastructure and Pilot

Reviewed engagement

Scopes private controls, evidence posture, and implementation requirements before any production deployment.

Compliance disclaimer

SigmaX provides capital decision intelligence, scenario analysis, and authority workflow software. SigmaX does not provide investment advice. SigmaX does not place trades, move funds, route customer capital, or manage client capital. Shadow/simulated/paper/backtested results are not live trading results. No result is a guarantee of future performance. Human approval is required before any capital-linked action.

Where SigmaX uses AI, it is governed as assistive software: truthful capability claims, human oversight, traceable records, disclosure of AI assistance, and no capital authority. SigmaX designs AI controls with reference to applicable securities obligations, FINRA existing-rule guidance, SEC AI-claims discipline, NIST AI RMF-style risk management, and EU AI Act transparency readiness. This is compliance-readiness design, not a claim that every deployment or jurisdiction-specific use has completed legal review.

Start your security review here.

Access reviews and diligence start from verifiable records, least-privilege scoped access, and no customer capital-movement path in the enabled product. Ask for the detail your team needs.