Product · Sigma · AI & agent security · supply chain trust
Sigma.
A high-security platform for AI agents and software supply chains — controlling data, models, tools and actions while providing cryptographic evidence for the software you deploy.
- Area
- AI security + supply chain trust
- Status
- In development
- For whom
- Companies running AI, agents and critical software supply chains
- Protects
- Data · agents · models · tools · actions · artefacts
- Availability
- Pilot customers wanted
AI agents can read data, call tools and execute actions. Production software also passes through many dependencies and build steps. Without controls, it becomes difficult to prove what happened and what was actually shipped.
Sigma puts controls in front of data, models, tools and actions: secret detection, input and output guards, agent/model/tool trust, and a tool-and-action firewall with approvals. In parallel, Sigma proves software provenance with SBOMs, provenance, signed attestations and VEX.
Features
03 04 modulesAI gateway & data guard
Input and output policies, secret detection, vault integration, plus signals for prompt and tool poisoning.
Agent, model & tool trust
Registries, signed agent manifests and revocations define which identities and tools are trusted in the first place.
Tool & action firewall
Tool calls and risky actions are checked against policies and parameters before execution, with human approval where needed.
Supply chain trust
SBOMs, in-toto provenance, Ed25519 attestations and VEX provide cryptographic evidence through to the artefact.
You have an idea? We'll make it happen.
Whatever you have in mind — a frontend or a complete system — we'll be happy to take it from planning through to production.