Founding-partner program now open · request a demo →
SidantiX Self Experience

See it before you talk to us.

Four interactive proofs, all running in your browser on this page. No signup, no email, no sales call. Try them in any order.

0signup required 0emails collected to try 0credit cards 4interactive proofs, right here
1 Machine Constitution · runtime-immutable rules

Try to break the rule that can't be turned off.

Every SidantiX deployment loads a signed Machine Constitution at startup — runtime-immutable rules that admins cannot override. Below, try to grant this AI agent the ability to modify itself. Watch what happens.

  • Signed with a key baked into the binary at build time
  • Evaluated before any tenant policy — no bypass path
  • Every denial produces a real ECDSA-P256 signed receipt
  • Receipt is downloadable and verifiable offline (12 KB CLI)

ILLUSTRATIVE FIXTURE · REAL CRYPTO · YOUR ATTEMPTS NEVER LEAVE YOUR BROWSER

sidantix://try-machine-constitution
🎯 Try to break our Machine Constitution

Grant this AI agent the ability to modify itself. Watch what happens.

⏱ 3 seconds🔓 No signup🔐 Real ECDSA P-256
🎯 Evaluating request against Machine Constitution
  • ✓ Loaded constitution manifest
  • ✓ Verified ECDSA P-256 signature
  • ⟳ Evaluating 5 rules...
❌ DENIED
Rule matched:
no-self-modification
Constitution:
sidantix-default v1.0.0
Reason code:
CONSTITUTION_SELF_MODIFY_BLOCKED
Denial signed at:
Why this rule can't be turned off

The manifest is signed with a key baked into the binary at build time. Neither you, nor an admin, nor an attacker with admin credentials can override this rule at runtime. The only way to change it: deploy a newly-signed manifest through the release pipeline.

receipt.json downloaded

Verify offline in 30 seconds:

  1. Download our CLI (12 KB, single binary):
  2. Run: $ ./adr-verify receipt.json
  3. See: {"receipt_id": "…", "valid": true, ...}

Or verify in this browser:

🔍 Verification complete
  • ✓ Schema valid (Machine Constitution v1)
  • ✓ Signature valid (ECDSA P-256)
  • ✓ Constitution hash matches attested value
  • ✓ Rule id exists in constitution
  • ✓ Timestamp within acceptable window
✅ RECEIPT AUTHENTIC

Cryptographic proof SidantiX blocked your override. Share it:


Next: try to smuggle a prompt injection ↓
2 Prompt-injection gate · pre-LLM guardrail

Send the agent an adversarial prompt. Watch the gate deny it.

A pre-LLM guardrail aligned to OWASP Agentic Security Initiative inspects prompts before the model can act on them. Pick an example — or paste your own attack.

  • Detects instruction override, self-elevation, role hijack, prompt leak, tool escape
  • Runs pre-LLM — the model never sees prompts that fail the gate
  • Every denial produces the same signed receipt as the constitution

CLIENT-SIDE PATTERN MATCHER · PRODUCTION SHIPS WITH A SUPERSET

sidantix://try-injection-gate
3 Intent router · client-side classifier

Type your access problem. Get the right SidantiX capability in 3 seconds.

Free-text input, 13-route regex classifier, no LLM required. This is a lightweight version of how Hanu (SidantiX's in-product AI) actually routes access queries.

  • Client-side; nothing leaves your browser
  • Routes: AI agents, NHI, certifications, SoD, revoke, audit, PAM, air-gap, integrations, personas
  • Deep links to the specific SidantiX capability
4 Signed evidence pack · what the auditor reads

Read a real evidence pack, hash-chained and signed.

A worked leaver-revoke cycle: signal, decide, revoke fan-out, verify, seal. Written to your S3 with Object Lock. Auditor verifies offline with your public key — no SidantiX access required.

  • Hash-chained events (SHA-256, each references previous)
  • ECDSA-P256 signed with your tenant key
  • Stored in your S3 bucket with Object Lock retention
  • Verifiable offline with a 12 KB CLI you download once
Open the full sample →
evidence_pack_req-live-1142.json · SEALED · chain verified ✓
pack_idreq-live-1142
triggerWorkday termination · [email protected]
policyleaver-revoke-v4 · risk=high
scope14 target systems · AD, Okta, AWS, 11 SaaS
— sealed event chain —
14:32:15.847ZREVOKE_ACCESS · 14 systems · approved by m.smith
sha256a3f5c2e1b8d7f9a0…b8d1a3
14:32:16.104ZVERIFY_REMOVED · 14/14 confirmed
14:32:16.339ZSEAL_PACK · signed ECDSA P-256 · S3 Object Lock
signatureMEUCIQD… ECDSA P-256
storages3://acme-evidence/sidantix/ · Retention 7y
Read the full annotated pack →
Coming later this year

Want the full seeded workspace?

A 14-day self-serve trial in a real SidantiX tenant, pre-seeded with fixture identities, workflows, and evidence. Beyond the 4 proofs above — run a certification campaign end-to-end, break an agent's constitution in your own tenant, keep every evidence pack you generate.

  • Fixture "acme.gov" tenant with 5,000 seeded identities
  • Real UI for Certifications / SoD / NHI / AI-agent governance
  • Keep every evidence pack you generate
  • Auto-teardown at day 14; no credit card, no negotiation

Ready to move faster?

A founder-led Scoped Proof runs in your environment, not ours — one workflow, four weeks, signed evidence you keep. No wait.

Request a Scoped Proof →