Founding-partner program now open · request a demo →

The platform · full module matrix

Four layers. Twenty pillars.

Four layers and twenty pillars grouped by the job each capability does, with an honest read on what's live, in beta, or planned. No green-check theater.

Live today In beta Planned

Every Live / Beta / Planned claim on this page is restated in your order form or SOW — we don't say something ships today unless we'll put it in the contract. Beta means it runs but hasn't cleared our full production bar yet; Planned means it's scoped and dated but not written yet.

SidantiX Governance OS workspace — illustrative product screenshot
Product screenshot · illustrative data
01

Govern

Normalize every identity — human, non-human, and AI-agent — into one graph, and certify against real maturity.

You can't govern what you can't see. Most teams can't name half their service accounts, let alone their AI agents — so governance starts by making every identity visible in one place.

Unified identity graph Live

Human users, service accounts, API keys, and AI agents correlated across legacy and cloud into a single, queryable graph.

Access certifications Live

Campaigns that end in an auditor-grade evidence pack — reviewers certify against real access, not stale entitlements.

Access catalog & requests Beta

Self-service requests, approvals, and automatic reconciliation against the systems of record you already run.

02

Protect

Catch toxic access, dormant power, and AI-agent risk before it becomes an incident.

The access that causes breaches is rarely new — it's the dormant admin rights and quietly over-privileged agents nobody revisited. Protect is about catching those before an attacker does.

Segregation of duties Live

Detect and block toxic access combinations before they're granted, with policy you can read and audit.

Dormant & over-privileged access Beta

Surface dormant admin accounts, unused entitlements, and over-privileged agents that quietly accumulate risk.

AI-agent prompt-injection gate Beta

A pre-LLM guardrail aligned to OWASP ASI — inspect tool-use and prompts before an agent can act on them.

Try the guardrail

Ship the prompt. See the guardrail deny it.

Type an adversarial prompt below. SidantiX's pre-LLM prompt-injection gate — aligned to OWASP ASI — inspects the prompt before your agent can act on it, and produces a signed denial receipt. Try one of the example patterns or write your own.

  • Detects instruction override, self-elevation, role hijack, system-prompt leak, tool escape
  • Runs pre-LLM — the model never sees prompts that fail the gate
  • Every denial produces the same ECDSA-P256 receipt as any other decision
sidantix://try-injection-gate
03

Revoke

One signal in, revoke fans out everywhere — closed-loop, outbound-only, verified.

Most tools tell you a revoke was requested. The question an auditor actually asks is whether it happened — across every system, with proof. Revoke isn't done until removal is verified and sealed.

Closed-loop revoke Live

HR or IdP signal triggers revoke across AD, Okta, AWS, and SaaS in seconds — then verifies removal actually happened.

Kill switch & dual control Live

Compromised account? Dry-run, two-person approval, revoke everywhere, verify, and seal — one controlled motion.

Outbound-only gateway Live

A customer-managed gateway dials out over mTLS. No inbound ports to open — built for restricted networks.

04

Prove

Every decision sealed into tamper-evident evidence on storage you control.

This is the gap I spent 26 years watching go unanswered: the decision lived in one system, the proof in spreadsheets and email. Prove makes the evidence math — verifiable on your own, without trusting us.

Hash-chained evidence packs Live

Every revoke, grant, and approval sealed into a SHA-256 hash-chain, signed with ECDSA — change one record and the chain breaks.

Customer-controlled storage Live

Evidence written to your own S3 with Object Lock and retention boundaries you set. Your keys (BYO-KMS) — we can't read it without you.

One-click audit export Beta

Generate a framework-mapped evidence pack (e.g. SOX §404) on demand — verifiable offline, without trusting us.

Module matrix

Twenty pillars. One control plane.

Each pillar maps to a module in SidantiX — evidence-first identity governance across humans, machines, and AI agents.

Access RequestsAccess RequestsBeta
ApprovalsApprovalsBeta
Ask SidantiXAsk SidantiXBeta
Audit TimelineAudit TimelineBeta
Break GlassBreak GlassLive
Certifications and UARCertifications & UARLive
CIEMCIEMBeta
ConnectorsConnectorsLive
Digital TwinDigital TwinPlanned
Evidence PackEvidence PackLive
Identity LifecycleIdentity LifecycleLive
JIT Privileged AccessJIT Privileged AccessBeta
NHI and Service AccountsNHI & Service AccountsLive
Policy EnginePolicy EngineLive
ProvisioningProvisioningLive
RBAC and ABACRBAC & ABACLive
ReconciliationReconciliationLive
Risk EngineRisk EngineBeta
Segregation of DutiesSegregation of DutiesLive
UEBA and ThreatUEBA & ThreatBeta

See it run in your environment.

A scoped proof shows these capabilities working against your real systems — and hands you the evidence pack to keep.