Proof your vendor's AI
isn't stealing
your data.
You have a third-party AI on your infrastructure. You approved the contract. But you have no idea what it's actually doing on your network. Sigilla enforces the boundary — and gives your auditor cryptographic proof.
Free pilot programme open. Three months free — in exchange for honest feedback and one reference call if Sigilla delivers value.
Your auditor needs evidence,
not promises.
Regulated industries are deploying third-party AI — and discovering they have no way to prove those systems are contained. That gap is now a legal problem.
The vendor's AI is a black box
You approved the contract. You read the DPA. But you cannot see what the application is actually doing on your network at runtime. It declared three destinations. Is that all it uses? You don't know.
Compliance evidence takes 40+ hours per audit
ISO 27001 auditors ask for network segmentation evidence. GDPR auditors ask for data flow proof. EU AI Act auditors need human oversight logs. Every audit is 40+ hours of manual collection from systems not designed for it.
August 2026 is closer than you think
EU AI Act enforcement begins . High-risk AI systems need audit trails, technical documentation, and human oversight evidence. Fines reach €35M or 7% of global revenue. Most companies have none of it ready.
Trust is not a compliance answer
Your vendor is probably not malicious. But "probably" is not what an auditor accepts. When they ask for proof of data sovereignty, a contract is not proof. A cryptographically signed, independently verifiable log is proof.
Three steps to
auditor-ready proof.
Your vendor tells Sigilla exactly which servers their AI is allowed to contact. That list is locked in. They cannot add to it later without your approval.
Your IT team installs the package in 30 minutes. From that moment, any attempt by the AI to contact an unlisted server is automatically blocked and logged. You don't have to do anything.
When your auditor asks for evidence, you open the Sigilla dashboard, click Generate Report, and hand them a signed PDF. They can verify it themselves. The audit takes minutes, not weeks.
Technical detail below — for your IT team
Vendor packages their application
The vendor declares every network destination their app needs. That declaration becomes the enforcement policy. Sigilla allows only what was declared — everything else is blocked at the kernel level.
egress:
- sensor-db.internal:5432
→ Everything else: DENY
You deploy — fully isolated
Drop the package into your Sigilla dashboard. Network isolation applies instantly. The vendor cannot bypass this — not with a software update, not intentionally. Every connection attempt is logged in real time.
-s [app-ip] -j REJECT
iptables -I FORWARD \
-d sensor-db:5432 -j ACCEPT
Generate your compliance report
Select ISO 27001, GDPR, or EU AI Act. Pick a date range. Click Generate. A cryptographically signed PDF downloads. Your auditor verifies it with openssl — no Sigilla account, no internet, no trust required.
-CAfile sigilla-public.pem \
report-iso27001-q1-2026.pdf
→ OK ✅
Sigilla solves a different problem.
Credo AI, Holistic AI, Vanta — excellent for governing your own AI. None of them answer: what is the vendor's AI doing on your network right now?
| Capability | Sigilla | Credo AI | Holistic AI | Vanta |
|---|---|---|---|---|
| Prove vendor AI network behaviour at runtime | ✓ | ✗ | ✗ | ✗ |
| Kernel-level isolation (cannot be bypassed) | ✓ | ✗ | ✗ | ✗ |
| Cryptographically signed compliance reports | ✓ | ✗ | Partial | Partial |
| Works fully offline / air-gap | ✓ | ✗ | ✗ | ✗ |
| EU AI Act runtime oversight evidence | ✓ | Docs only | Docs only | ✗ |
| Govern your own internal AI systems | ✗ | ✓ | ✓ | ✓ |
What to ask your vendor.
Word for word.
The hardest part is often knowing how to start the conversation. Here's exactly what to say — and what to expect back.
What you need
to run this.
No new hardware. No cloud account. No specialist Linux knowledge beyond what your IT team already has.
- Operating system Ubuntu 22.04 LTS (standard server)
- CPU / RAM Standard x86 server — no GPU required
- Network Internal network access only — air-gap capable
- Internet Not required — works fully offline
- Installation ~30 minutes per vendor application
- Ongoing work Dashboard review + update approvals only
- ✓No cloud subscription or SaaS account
- ✓No GPU or specialised hardware
- ✓No changes to your existing infrastructure
- ✓No data sent to Sigilla servers
- ✓No vendor-specific IT expertise
- ✓No ongoing maintenance beyond update approvals
The regulations driving
urgency right now.
High-risk AI audit trails
Article 12 requires logs for the full lifetime of high-risk AI. Sigilla generates this automatically at runtime.
Change management evidence
Critical infrastructure operators must demonstrate change management. Sigilla provides a 7-event update audit chain.
Provable data sovereignty
Sovereignty must be demonstrable. Sigilla provides cryptographic proof that data never left your infrastructure.
Network segmentation evidence
Control A.13 requires demonstrable network segmentation. Sigilla provides kernel-level enforcement plus signed evidence.
Everything your auditor
needs to say yes.
Kernel-level isolation
iptables default-deny that cannot be bypassed from inside the container. Enforcement at the OS level, not a policy document.
Real-time activity feed
Every connection logged within 10 seconds. Blocked calls to external servers show up immediately. You have never had this visibility.
60-second compliance reports
ISO 27001, GDPR, EU AI Act. Cryptographically signed PDFs. Independently verifiable with openssl — no account needed.
Cryptographic audit chain
Hash-linked event log. Tamper with any entry and the chain breaks — detectable by anyone with a terminal.
Update approval workflow
Every vendor update shows exactly what changed in the network policy. Your approval is logged — that's your EU AI Act human oversight evidence.
Air-gap capable
Zero internet required. Every site runs independently. Required for rail, critical infrastructure, and defence-adjacent environments.
Designed for contained AI.
Not everything. Deliberately.
Sigilla enforces a static network policy declared upfront. That works perfectly for a large class of industrial AI — and we want to be precise about what that class is, so you know exactly what you're buying.
The roadmap follows
where regulation is heading.
The EU AI Act is most concerned about high-risk agentic systems. That's exactly where we're building next — runtime intervention, local model governance, and dynamic policy.
Three months free.
No commitment.
We're accepting a small number of pilot customers for 2026. Free access in exchange for honest feedback — and one reference call if Sigilla delivers real value. The EU AI Act deadline is August 2026. Starting now gives you time to get it right.
No spam. Personal reply within 48 hours.