Technical Control Assurance

Provable security assurance for MSPs.

SigXOS captures network configurations locally and read-only, evaluates them with versioned deterministic rules, and produces findings and evidence that stay technically traceable.

  • Read-only
  • Local-first
  • Controlled AI
  • Generation 1 makes no changes
assessment / SW-CORE-01 READ ONLY

F014Gi1/0/12Rule version 1.3.0

Unsafe port negotiation

FAIL HIGH

Actual state

switchport mode dynamic auto

Target state

switchport mode access
switchport nonegotiate
The rule decides. AI explains, optionally.

Schematic view from the PoC

22deterministic rules implemented
0claimed as fully validated
4–6week MSP pilot
10–25assets in pilot scope

Technical assurance is still manual work

Same controls, every time from scratch.

MSPs and IT service providers check similar technical controls again and again, across many regulated customers. The effort is high, quality varies, and the knowledge does not scale.

Complexity

Vendors, baselines and requirements keep changing and have to be reassessed regularly.

Evidence gap

The real technical state lives across different tools and teams — and is hard to prove.

Expert effort

Checks, reports and re-tests are rebuilt for every customer environment.

Growing reporting duties meet limited security capacity: 70 % name compliance as a driver of their security investments, 76 % report difficulties hiring staff and 71 % retaining them. Source: ENISA, NIS Investments 2025.

The SigXOS solution

A read-only assurance layer.

Four components working together — for MSPs and regulated organisations.

Assurance Platform

Manage

Customers, assets, findings, exceptions, history and re-verification in one place.

SigXOS Edge

Inspect locally

Captures and evaluates configurations read-only inside the customer environment.

Control Intelligence

Maintain knowledge

Versioned, validated rules and the technical semantics behind them.

Controlled AI

Explain

Puts results in context and prioritises actions — without setting a technical status.

The customer decides. SigXOS changes no infrastructure.

From configuration to evidence

Expert knowledge becomes repeatable.

Five steps, from the source of a rule to reliable proof.

1

Knowledge and requirements

Vendor knowledge, security baselines and regulatory reference frameworks form the basis.

2

Control Intelligence

These become validated rules, tests and mappings — versioned and reusable.

3

SigXOS Platform

Distributes the rules to the edge components and governs evidence, history and re-verification.

4

Edge at the customer

Captures over read-only SSH, normalises the technical state and checks deterministically on site.

5

Result

Prioritised findings with rule version, asset, timestamp and redacted technical proof.

SigXOS

Maintains and validates the rules.

MSP or customer

Provides the context and decides.

Controlled AI

Explains and correlates — does not decide.

Credentials stay local. Generation 1 makes no changes to customer devices. PASS, FAIL, UNKNOWN, NOT APPLICABLE and ERROR are produced deterministically; AI changes none of these states. Missing or filtered information never leads to a passing result.

The product core

Validated once, reused many times.

SigXOS does not rebuild check logic for every customer. Control Intelligence makes expert knowledge versionable, testable and reusable.

Reliable check results

PASS, FAIL and UNKNOWN are produced deterministically — not by a language model.

Reusable expert knowledge

Control semantics, test logic and platform or version differences are maintained centrally.

Traceable proof

Source, rule version and result stay documented across the full history.

AI with clear limits

AI explains and prioritises without altering technical results.

Whether this becomes a lasting competitive advantage is an assumption. The pilot measures it against reuse, engineer time, and false-positive and false-negative rates.

Honest product status

What runs, and what the pilot must show.

In the PoC today

Tested within the documented scope

  • Read-only SSH capture
  • Cisco IOS and IOS-XE within the tested scope
  • Deterministic check engine implemented
  • Findings, evidence and reports available

To be proven in the pilot

Open and deliberately named

  • Validate rule quality reliably
  • Close re-verification end to end
  • Measure time saved for MSP engineers
  • Test price and willingness to pay

No claim is made of full CIS, NIS2 or BSIG conformity. SigXOS supports technical checking and evidence processes. Further vendors are prioritised only once a concrete pilot or partner need exists.

Local-first architecture

Raw data stays close to the customer network.

The planned edge platform separates local capture and rule checking from the approved, minimised control channel.

Customer network

Cisco IOS / IOS-XE

Routers and switches within the approved scope.

SigXOS Edge

Capture and rules

Local checking, local evidence. Credentials and full configurations stay on site.

SigXOS Platform

Control Plane

Rule distribution, history and approved finding context in an EU/EEA data centre.

Rules decide. AI explains, optionally. People review and approve.

Commercial model

Recurring B2B software for MSPs.

MSP platform

Base fee for tenant, control library, API and support.

Recurring

Customer environment

Fee per managed customer environment.

Recurring

Asset packages

Predictable packages by number of assets checked.

Recurring

Optional services

Onboarding, rule packs and integrations.

Available on request

Pricing and packaging are not final. The pilot validates pricing logic and willingness to pay.

Go-to-market

Going to market through DACH MSPs.

MSPs and IT security providers

One partner reaches many customer environments. Similar controls repeat per customer — SigXOS turns that into a repeatable assurance service of their own instead of repeated manual work.

Regulated organisations

Traceable technical evidence in the NIS2 and BSIG context, with local processing and clear data boundaries.

Larger system houses, critical infrastructure and the public sector follow once product, security and compliance maturity allow.

MSP pilot

Start controlled. Learn measurably.

4–6weeks duration
10–25assets in scope
Read-onlyno changes
KPIstechnical and commercial
  • Cisco IOS/IOS-XE within the approved scope
  • Config completeness and negative write test as blockers
  • Prioritised findings, evidence and a closing review
  • No autonomous change and no claim of production readiness

The pilot measures engineer time, evidence effort, false positives, false negatives and willingness to pay.

Team

Two founder roles, one clear fit.

Parham Mahzari

Founder & CEO

  • Strategy and positioning
  • MSP partnerships and pilots
  • Business model and funding
  • Customer validation

James Bedford

Co-Founder & CTO

  • Product and platform development
  • Edge and technical architecture
  • Product security and integrations
  • Pilot Engineering

Next role: Control Intelligence Lead

Owns check logic, vendor knowledge and quality. To be hired after technical and commercial pilot validation.

Does SigXOS fit your environment?

In 30 minutes we clarify scope, asset profiles, AAA prerequisites and the possible pilot value.

Request a 30-minute scoping call