1. What Sigigo provides
Sigigo is evidence infrastructure: automatic, tamper-evident, independently verifiable audit records for significant actions in software, AI agents, and enterprise workflows.
Sigigo provides evidence infrastructure — cryptographically verifiable audit records. Sigigo is not a notified body, conformity assessment body, or certification service for the EU AI Act, CE marking, or any other regulatory scheme.
This page describes Sigigo's product posture and website practices. It is not legal advice. Customers remain responsible for their own regulatory classification, conformity assessment, and compliance programs.
2. EU AI Act (Regulation (EU) 2024/1689)
The EU AI Act requires high-risk AI systems to technically enable automatic logging over the lifetime of the system (Article 12). Deployers must monitor operation, retain logs for at least six months where applicable (Article 26), and support oversight, incident reporting, and post-market monitoring.
Sigigo helps providers and deployers implement Article 12 automatic, lifetime logging for high-risk systems — then adds a tamper-evident export layer with offline verification. We capture inference boundaries, human review, overrides, model metadata, and incident checkpoints using configurable ai_act.* event types. Cryptographic integrity is Sigigo’s evidence-quality layer, not an Article 12 mandate.
- Provider embed — AI vendors integrate the SDK so logging ships with the product.
- Deployer overlay — enterprises wrap vendor APIs to meet deployer duties directly.
- We do not perform conformity assessment, CE marking, or legal high-risk classification.
3. EU Data Act (Regulation (EU) 2023/2854)
The EU Data Act increases obligations around connected product data access, B2B sharing, cloud switching, and contractual fairness. Organizations need proof of access requests, share/suspend/withhold decisions, and migration integrity — not only policy documents.
Sigigo supports data_act.* events for access requests, fulfillment, switching milestones, and share execution with actor, timestamp, and scope references (not necessarily raw payloads).
4. GDPR and privacy engineering
Sigigo defaults to data minimization: reference identifiers over raw PII where possible, EU region pinning, public blockchain anchoring off unless approved, and Private Commitment Mode for sensitive workloads.
Deterministic hashes of personal data may still be personal data under GDPR. Commitment mode uses salted, unlinkable commitments held by the controller to narrow processor scope and support erasure programs.
See our Privacy Policy and DPA for processor obligations, SCCs, and data subject request support.
5. Data sovereignty profiles
Regulated industries and EU public-sector buyers often reject public-chain anchoring, cross-border metadata flows, or vendor-only audit UIs. Sigigo treats sovereignty profile as a first-class tenant configuration:
- Region-locked storage and API endpoints on AWS or Microsoft Azure (EU-sovereign deployment).
- Customer-managed keys (BYOK) and optional customer-operated transparency log mirrors.
- blockchainMode: disabled by default for strict profiles — cryptographic evidence without public ledger publication.
- Evidence export packages for auditor offline verification without trusting a single vendor dashboard.
6. Adjacent frameworks
Customers in financial services may align Sigigo evidence with DORA ICT resilience and incident documentation, NIS2 security logging, and sector-specific retention rules. Sigigo does not claim turnkey DORA or NIS2 certification — we provide verifiable records that fit into your control framework.
Healthcare, PCI, and US federal customers should review our Use Cases and sovereignty matrix with legal/security teams before selecting deployment modes.
7. Security practices
Production services use encryption in transit, access controls, signed events, append-only evidence chains, and audit logging of administrative actions. We perform vulnerability management and review sub-processor security.
Enterprise customers may request security documentation and questionnaires during procurement.
8. What we are not
Sigigo is not:
- A notified body or EU AI Act conformity assessment provider.
- A replacement for your quality management system or technical documentation.
- Legal counsel — customers must obtain independent advice on classification and obligations.
- A guarantee of regulatory compliance — compliance is an organizational outcome supported by evidence.