Pilot programmeWe are looking for design partners. Cisco IOS/IOS-XE is available in the prototype, further vendors on an individual plan. Learn more

Product

SigXOS collects configurations agentless, checks them against defined security rules and documents every finding with evidence.

PrototypeStatus October 2026: working prototype, technically tested with Cisco devices and simulators. Validation in a customer pilot is the next step.

Features

What SigXOS does today

The prototype runs with Cisco IOS and IOS-XE as its first rule library.

  • Agentless collection

    Collect configurations via SSH, read-only and without software on the devices.

  • Rule library

    22 CIS-oriented rules with CIS reference and severity.

  • Findings with evidence

    Every finding points to the configuration it refers to.

  • Device inventory

    Collected devices at a glance.

  • Audit trail

    Check events and results documented in a traceable way.

  • Check report

    Results of a check run as a report.

Inside the prototype

Original views from the prototype with lab data.

Screenshot from the SigXOS prototype: rule catalogue with 22 active rules, F001 to F010 visible, each with CIS reference and severity
Rule catalogue in the prototype, excerpt showing 10 of 22 rules. View all 22 rules
Screenshot from the SigXOS prototype: finding F007 “No VTY Access Control List Configured” with evidence that no access-class configuration is present
Finding with evidence in the prototype. Lab data. Open full size

Architecture

Agentless, read-only, local in the pilot

SigXOS reads configurations through existing access paths. In the pilot, collection and storage run in your environment.

Supported systems

Platforms and vendors

Today the prototype supports Cisco IOS and IOS-XE. For further network vendors we build the rule library on request, with an individual timeline and plan agreed with you. Cloud and identity systems are planned.

VendorPlatformStatus
CiscoIOS / IOS-XEPrototype
HPE Aruba NetworkingAOS-CXOn request
FortinetFortiOSOn request
Palo Alto NetworksPAN-OSOn request
HPE Juniper NetworkingJunos OSOn request
MicrosoftEntra ID and Active DirectoryPlanned

Vendor and product names belong to their respective owners. They are named to describe the technical context and do not imply a partnership.

Security and privacy

Principles for access and data

  • Read-only access

    SigXOS reads configurations and makes no changes to devices.

  • Agentless

    No software is installed on the devices.

  • Local in the pilot

    In the pilot, collection and storage stay in your environment.

  • Reproducible

    The same configuration state gives the same check result.

Licensing

Annual licence after the pilot

After a successful pilot, an annual licence is planned.

  • Base fee and device scope

    The annual licence consists of a base fee and the number of devices.

  • Prices and packages

    Prices and packages are not final yet.

Outlook

Extensions

  • Further network vendorsOn request
  • Cloud and identity systemsPlanned
  • Further evidence sourcesPlanned
  • Mapping to further frameworksPlanned
  • Partner programmePlanned

The prototype works with lab data. SigXOS does not claim full CIS, NIS-2 or BSIG conformity and does not replace a certification or legal advice.

Is SigXOS a fit for your environment?

You need to check and prove configurations regularly? Let’s find out in 30 minutes whether a pilot makes sense: directly with Cisco IOS/IOS-XE, with other vendors on an individual timeline and plan.