
Product
SigXOS collects configurations agentless, checks them against defined security rules and documents every finding with evidence.
PrototypeStatus October 2026: working prototype, technically tested with Cisco devices and simulators. Validation in a customer pilot is the next step.
Features
What SigXOS does today
The prototype runs with Cisco IOS and IOS-XE as its first rule library.
Agentless collection
Collect configurations via SSH, read-only and without software on the devices.
Rule library
22 CIS-oriented rules with CIS reference and severity.
Findings with evidence
Every finding points to the configuration it refers to.
Device inventory
Collected devices at a glance.
Audit trail
Check events and results documented in a traceable way.
Check report
Results of a check run as a report.
Inside the prototype
Original views from the prototype with lab data.


Architecture
Agentless, read-only, local in the pilot
SigXOS reads configurations through existing access paths. In the pilot, collection and storage run in your environment.
Your environment in the pilot
- Network devicesCisco IOS / IOS-XE
- CollectionSSH, read-only
- Rule checkRule library
- Findingswith configuration evidence
- Reportand audit trail
Supported systems
Platforms and vendors
Today the prototype supports Cisco IOS and IOS-XE. For further network vendors we build the rule library on request, with an individual timeline and plan agreed with you. Cloud and identity systems are planned.
| Vendor | Platform | Status |
|---|---|---|
| Cisco | IOS / IOS-XE | Prototype |
| HPE Aruba Networking | AOS-CX | On request |
| Fortinet | FortiOS | On request |
| Palo Alto Networks | PAN-OS | On request |
| HPE Juniper Networking | Junos OS | On request |
| Microsoft | Entra ID and Active Directory | Planned |
Vendor and product names belong to their respective owners. They are named to describe the technical context and do not imply a partnership.
Security and privacy
Principles for access and data
Read-only access
SigXOS reads configurations and makes no changes to devices.
Agentless
No software is installed on the devices.
Local in the pilot
In the pilot, collection and storage stay in your environment.
Reproducible
The same configuration state gives the same check result.
Licensing
Annual licence after the pilot
After a successful pilot, an annual licence is planned.
Base fee and device scope
The annual licence consists of a base fee and the number of devices.
Prices and packages
Prices and packages are not final yet.
Outlook
Extensions
- Further network vendorsOn request
- Cloud and identity systemsPlanned
- Further evidence sourcesPlanned
- Mapping to further frameworksPlanned
- Partner programmePlanned
The prototype works with lab data. SigXOS does not claim full CIS, NIS-2 or BSIG conformity and does not replace a certification or legal advice.
Is SigXOS a fit for your environment?
You need to check and prove configurations regularly? Let’s find out in 30 minutes whether a pilot makes sense: directly with Cisco IOS/IOS-XE, with other vendors on an individual timeline and plan.