The platform · full module matrix
Four layers and twenty pillars grouped by the job each capability does, with an honest read on what's live, in beta, or planned. No green-check theater.
Every Live / Beta / Planned claim on this page is restated in your order form or SOW — we don't say something ships today unless we'll put it in the contract. Beta means it runs but hasn't cleared our full production bar yet; Planned means it's scoped and dated but not written yet.
You can't govern what you can't see. Most teams can't name half their service accounts, let alone their AI agents — so governance starts by making every identity visible in one place.
Human users, service accounts, API keys, and AI agents correlated across legacy and cloud into a single, queryable graph.
Campaigns that end in an auditor-grade evidence pack — reviewers certify against real access, not stale entitlements.
Self-service requests, approvals, and automatic reconciliation against the systems of record you already run.
The access that causes breaches is rarely new — it's the dormant admin rights and quietly over-privileged agents nobody revisited. Protect is about catching those before an attacker does.
Detect and block toxic access combinations before they're granted, with policy you can read and audit.
Surface dormant admin accounts, unused entitlements, and over-privileged agents that quietly accumulate risk.
A pre-LLM guardrail aligned to OWASP ASI — inspect tool-use and prompts before an agent can act on them.
Type an adversarial prompt below. SidantiX's pre-LLM prompt-injection gate — aligned to OWASP ASI — inspects the prompt before your agent can act on it, and produces a signed denial receipt. Try one of the example patterns or write your own.
Most tools tell you a revoke was requested. The question an auditor actually asks is whether it happened — across every system, with proof. Revoke isn't done until removal is verified and sealed.
HR or IdP signal triggers revoke across AD, Okta, AWS, and SaaS in seconds — then verifies removal actually happened.
Compromised account? Dry-run, two-person approval, revoke everywhere, verify, and seal — one controlled motion.
A customer-managed gateway dials out over mTLS. No inbound ports to open — built for restricted networks.
This is the gap I spent 26 years watching go unanswered: the decision lived in one system, the proof in spreadsheets and email. Prove makes the evidence math — verifiable on your own, without trusting us.
Every revoke, grant, and approval sealed into a SHA-256 hash-chain, signed with ECDSA — change one record and the chain breaks.
Evidence written to your own S3 with Object Lock and retention boundaries you set. Your keys (BYO-KMS) — we can't read it without you.
Generate a framework-mapped evidence pack (e.g. SOX §404) on demand — verifiable offline, without trusting us.
Each pillar maps to a module in SidantiX — evidence-first identity governance across humans, machines, and AI agents.
A scoped proof shows these capabilities working against your real systems — and hands you the evidence pack to keep.