Founding-partner program now open · request a demo →
The First IGA With Proof

Every identity governed.
Every action proven.

Autonomous IGA for humans, machines, and AI agents.
With proof built in.

Built by a founder with 26 years in identity governance at IBM & Oracle.

Founder-led · Scoped proof · Full lifecycle IGA
sidantix://leaver-revoke · live proof cycle ILLUSTRATIVE
IDENTITY TRIGGER · j.doe@acme.gov
Workday termination · 14:32Z
Signal
Decide
Reach
Revoke
Prove
WDWorkday HCMGA✓ revoked
ADActive DirectoryGA✓ revoked
AADEntra IDGA✓ revoked
OKOktaGA✓ revoked
AWSAWS IAMGA✓ revoked
SNServiceNowBeta✓ revoked
AGENT ACTION · acme.gov · 22 IDENTITIES · AUTO-DISCOVERY
AIlangchain-prod-agentscanning…✓ governed
SVCsvc-workday-hrisscanning…✓ certified
KEYgithub-ci-tokenscanning…✓ rotated
BOTrpa-bot-finance-01scanning…✓ certified
IAMaws-deploy-orphan-23scanning…↻ revoking
AIbedrock-agent-87scanning…⚠ risk 87
EVIDENCE PACK · SEALED
hash-chained
sha256: a3f5c2e1b8d7f9a0c4e6…b8d1a3e5
prev: 7c2e1a48b7f9d3e6 · customer retention
SidantiX governance workspace — illustrative product screenshot
Product screenshot · illustrative data
Not sure where to start?

Tell us the access problem. Get a 30-second path.

Type it in your own words — we'll point you at the SidantiX capability, walkthrough, or contact path that fits. No signup, no email required.

<5min
Target: leaver to fully revoked
0
Inbound firewall ports
12
Governance modules
100%
Target: of actions sealed

Full lifecycle IGA · proof on every decision

JMLAccess RequestsCertificationsSoDMachine IdentityAI Agent GovernanceEvidence Packs
Why teams choose SidantiX

Full IGA. Proof built in.

Three outcomes that matter at audit time — full lifecycle governance with cryptographic proof on every decision.

Prove every decision

Hash-chained evidence packs on storage you control. When the auditor says prove it, you verify offline — no vendor trust required.

Close the revoke loop

HR signal in, revoke fans out across AD, Okta, AWS, and SaaS — then verifies removal and seals the proof.

Govern humans, machines & AI

22+ non-human identity types and AI agents as first-class citizens — the gap legacy IGA was never designed to close.

Customer scenarios

Where proof changes the outcome.

SidantiX is a full IGA platform built for the access problems identity teams actually face — with verifiable closure on every one.

1

High-risk leaver remediation

Signal in, revoke across apps and privileged paths, verify removal, and seal an evidence pack the auditor can read.

2

AI-agent tool governance

Prove which agent used which tool, under which policy, with what approval — then certify or revoke with the same chain.

3

Privileged service account reviews

Assign owners, certify entitlements, rotate stale secrets, and close the review with signed proof — not a checkbox.

4

SoD exception closure

Track reason, expiry, approver, mitigation, and verified remediation — so exceptions do not become permanent access.

5

Cloud entitlement drift

Detect risky drift across cloud roles, policies, groups, and workload identities — then remediate and prove it closed.

6

Audit evidence readiness

Export decision, review, approval, remediation, and hash-chained proof artifacts when the auditor asks — in minutes, not weeks.

Product view

One workspace for humans, machines, and AI agents.

Entity risk, decision context, and audit proof in one place — not scattered across tickets and slide decks.

SidantiX Evidence Workspace Illustrative data
721machine identities
43AI agent actions
19SoD exceptions
98%verified closure

High-risk entity review

Decision context, access owner, risk signal, and proof status in one view.

EntityTypeRiskProof
svc-payments-apiMachineElevatedSigned
AI-Agent-ProcureAI AgentAIVerified
J. ManagerHumanLowComplete
sap-firefighterPrivilegedTime-boundReceipt
Why SidantiX

Legacy IGA vs SidantiX.

Same governance jobs — certifications, provisioning, SoD, revoke — with proof that closes the loop.

Legacy IGA

Strong workflow records, but limited evidence context.
Human identity focus — weaker machine and AI-agent coverage.
Review completion does not always prove remediation closed.

SidantiX

Full lifecycle IGA with evidence-backed decisions and sealed proof.
Humans, machines, service accounts, APIs, workloads, and AI agents.
Closed-loop revoke with verified remediation and hash-chained packs.
Why trust a new name

"I spent 26 years building identity governance at IBM and Oracle. I kept watching the same audit question go unanswered — so I left to build the answer."

SG
Sirisha Gottipati
Founder, SidantiX · Sacramento, CA
26 yrs IGAIBMOracleFounder-led delivery
Founding-partner program · 2026

Be one of our first design partners.

We're deliberately choosing a small group — not chasing logos. Each founding partner gets founder-led implementation and shapes the roadmap around their real constraints.

Limited 2026 cohort · applications open
Request a founding-partner conversation
The IGA

A complete IGA. Everything else is optional.

SidantiX is a full identity governance platform — humans, machines, and AI agents, all governed with cryptographic proof. It runs standalone. If you already own SailPoint, Okta, Entra, or legacy systems, SidantiX connects to them too — but nothing about SidantiX depends on them being there.

  • Complete on day one.Full lifecycle IGA — provisioning, requests, certifications, SoD, NHI, AI-agent governance, evidence. No missing pillars, no other vendor required.
  • No inbound firewall changes.A customer-managed gateway dials out over mTLS. Nothing to open.
  • Replace or coexist — your call.Run SidantiX as your primary IGA on day one, or run it in parallel with SailPoint / Saviynt while you migrate off them. Same full platform either way.
SidantiX
full IGA · verified revoke · tamper-evident evidence
↓  optional connections when they exist  ↓
IDP
Okta · Entra ID
LEGACY IGA
SailPoint · Saviynt
DIRECTORIES
Active Directory · LDAP
HR / ERP
Workday · PeopleSoft · SAP

Fits the stack you already run

Identity providers Directories HRIS / HCM Cloud IAM ITSM Legacy systems

Outbound connectors · SidantiX runs standalone, integrates with what you have. See integrations →

The platform

Four layers. One control plane.

Not 80 modules to read through — four jobs the platform does across the stack you already run. The full module matrix lives one level deeper, once you want it.

01

Govern

Normalize human, non-human, and AI-agent identities across legacy and cloud into one graph. Certify against real maturity, not green checks.

02

Protect

Detect toxic access, separation-of-duties violations, dormant admin agents, and prompt-injection at a pre-LLM gate — before it becomes an incident.

03

Revoke

HR signal in, revoke fans out across AD, Okta, AWS, and SaaS in seconds. Closed-loop, outbound-only, nothing left bleeding after a leaver.

04

Prove

Every decision hash-chained into a tamper-evident pack on customer-controlled S3 with retention boundaries you set. When the auditor says “prove it,” you do.

The evidence layer

When the auditor says "prove it."

Every revoke, grant, and approval is sealed into a tamper-evident chain and written to storage you control. Change one record and the chain breaks — so the evidence an auditor reads is the evidence of what actually happened.

The proof is math, and it's yours to keep — verifiable on your own, without trusting us.

100%
Of actions sealed & verifiable
1-click
Evidence pack for any audit
EVIDENCE CHAIN · req-live-1142 · extending
14:32:15.847Z · REVOKE_ACCESS S3 LOCKEDj.doe@acme.gov · 14 systems · approved by m.smithsha256: a3f5c2e1b8d7f9a0…b8d1a3e5
14:32:16.104Z · VERIFY_REMOVED14 / 14 confirmed · prev: 7c2e1a48…b9d4a6
14:32:16.339Z · SEAL_PACKevidence_pack_req-live-1142.json · chain verified ✓
Try to break it

The one rule nobody can override.

Every SidantiX deployment ships with a signed Machine Constitution — runtime-immutable rules the strongest admin cannot turn off. Grant an AI agent the ability to modify itself, and watch what happens. You'll leave with a cryptographic receipt you can verify offline.

  • Signed with a key baked into the binary at build time
  • Evaluated before any tenant policy — no bypass path
  • Every denial produces an ECDSA P-256 signed receipt (RFC 8785 canonical JSON)
  • Verifiable offline with a 12 KB single binary — no vendor call
sidantix://try-machine-constitution
🎯 Try to break our Machine Constitution

Grant this AI agent the ability to modify itself. Watch what happens.

⏱ 3 seconds🔓 No signup🔐 Real ECDSA P-256
🎯 Evaluating request against Machine Constitution
  • ✓ Loaded constitution manifest
  • ✓ Verified ECDSA P-256 signature
  • ⟳ Evaluating 5 rules...
❌ DENIED
Rule matched:
no-self-modification
Constitution:
sidantix-default v1.0.0
Reason code:
CONSTITUTION_SELF_MODIFY_BLOCKED
Denial signed at:
Why this rule can't be turned off

The manifest is signed with a key baked into the binary at build time. Neither you, nor an admin, nor an attacker with admin credentials can override this rule at runtime. The only way to change it: deploy a newly-signed manifest through the release pipeline.

receipt.json downloaded

Verify offline in 30 seconds:

  1. Download our CLI (12 KB, single binary):
  2. Run: $ ./adr-verify receipt.json
  3. See: {"receipt_id": "…", "valid": true, ...}

Or verify in this browser:

🔍 Verification complete
  • ✓ Schema valid (Machine Constitution v1)
  • ✓ Signature valid (ECDSA P-256)
  • ✓ Constitution hash matches attested value
  • ✓ Rule id exists in constitution
  • ✓ Timestamp within acceptable window
✅ RECEIPT AUTHENTIC

Cryptographic proof SidantiX blocked your override. Share it:


See this at 10,000 agents →
Try this in your environment

Questions that take seconds, not slide decks.

SidantiX's modules share one identity graph, one audit chain, one policy engine — so cross-module questions that no single-vendor stack can answer become a single query.

"Which service accounts can read our PCI data and haven't been certified in 90 days?
# GET /api/dspm/nhi-correlation?classification=PCI&uncertified=90d
$ 8 NHIs match.
→ aws-prod-billing-svc (IAM) — 142d
→ github-deploy-tok-prod (PAT) — 187d
→ stripe-webhook-key (API) — 211d
→ Auto-created micro-cert campaign in 2s.
"An employee changed roles yesterday. What happened next?
# GET /api/identities/49281/timeline
11:14 HR_EVENT Finance → Audit
11:14 SoD_CHECK toxic pair detected
11:15 MICRO_CERT campaign auto-created
11:18 APPROVAL by manager (Slack)
11:18 EVIDENCE_PACK #c8f3a91 signed & archived
"Show me every AI agent with admin permissions dormant 30+ days.
# GET /api/ispm/agents?dormantDays=30&permLevel=ADMIN
$ 3 agents flagged.
→ bedrock-incident-responder ASI10 · 47d
→ vertex-data-clean-up ASI10 · 89d
→ langchain-prod-deploy wildcard IAM · 62d
→ Owners notified. Cert review scheduled.
"Generate a SOX §404 evidence pack. Right now.
# POST /api/compliance/reports/sox-404/generate
→ joining cert_campaign × cert_decision…
→ joining platform_role × sod_violation…
→ hash-chaining 47,182 audit rows…
→ signing with tenant ECDSA key…
$ SOX_404_this-quarter.pdf — 8.3MB · verified · 4.2s

Illustrative query patterns · real queries return results from your identity graph

Trust

Built for environments that cannot afford to guess.

SLED, healthcare, and financial-services enterprises with strict network, evidence, and compliance requirements.

Active

SOC 2 Readiness

Readiness work in progress with a target assessment window. Formal status available under NDA.

Informed · Not authorized

FedRAMP

FedRAMP-informed architecture. Not authorized — we say so plainly.

Designed-to

NIST 800-53 Rev.5

AC, AU, IA & SI control families inform product design. Formal mapping in progress; not independently assessed.

Aligned

HIPAA Alignment

HIPAA-aligned deployment patterns for qualified environments. BAA terms reviewed during contracting.

Active

OWASP ASI

ASI-aligned controls for AI-agent governance, including pre-LLM prompt and tool-use guardrails.

Verified per build

Automated Security Checks

Release builds run automated security, quality, and dependency checks before signing.

Aligned

CIS Controls

Designed to support CIS-aligned secure configuration and network hardening.

Customer-owned

Hash-chained evidence

Every evidence pack hash-chained, signed, and stored in your own S3.

Compliance references describe current alignment, readiness, or planned assessment status and are not certifications unless stated in a signed customer artifact.

Founding-partner program

Prove it in your environment.

Be one of a small group of founding partners. Founder-led, scoped to one system, and designed to show real results in your environment before any broader commitment.

01
Connect
02
Discover gaps
03
Dry-run revoke
04
Live revoke + Evidence Pack
Start your scoped proof

Let's prove it in your environment.

Tell us one workflow you'd like to see proven — an off-boarding, a certification, a single policy. We'll come back within a few business days, founder to founder.

  • Founder replies personally
  • Scoped to one workflow — real evidence, real fast
  • We'll tell you honestly if we're not a fit
or email us directly at hello@sidantix.com