About SigmaShake

SigmaShake is AI Agent Guardrails. Agents may propose actions. SigmaShake independently evaluates whether those actions should be allowed, denied, escalated, or transformed before execution. Policy at the tool-call boundary. Honest-agent / integration-dependent. Not a sandbox. See also generative AI guardrails.

Our Mission

SigmaShake’s mission is to unlock the full potential of AI development through resilient, deterministic, and highly scalable security solutions.

We deliver uncompromising speed and reliability, ignoring market noise to focus entirely on engineering excellence.

What We Build

The ssg CLI and policy engine runs locally on your machine. It integrates with Claude Code, Cursor, VS Code Copilot, Gemini CLI, OpenHands, Aider, Windsurf, and any MCP-compatible agent. Rules are written in a declarative DSL with no LLM call, no regex tweak, just typed IF/THEN conditions evaluated at sub-millisecond speed before every tool action.

The Rules Hub hosts a community library of signed, auditable rule sets. The docs cover every adapter, DSL keyword, and deployment pattern. Pro and Enterprise teams get private rulesets (install from your own private GitHub repo or publish privately to the Hub for your team), fleet-wide sync, and SSO.

Security & Compliance

SigmaShake operates an ISO 27001:2022-aligned information security program. All 93 Annex A controls are catalogued, evidenced with daily Ed25519-signed internal evidence packs, and tracked via a live Statement of Applicability. This ISO 27001 program is self-assessed and not third-party certified; no external certification body has audited it. SOC 2 Type II readiness evidence is continuously collected: this is readiness only. The observation window is open (2026-05-18 to 2026-11-17), no independent CPA firm has been engaged, and the earliest realistic Type II report is Q1 2027. The full compliance posture is visible at trust.sigmashake.com.

Why It Exists

AI coding agents have root access to your machine. The default permission model is "Y/N" per command; which means you're either babysitting every keystroke or running in YOLO mode with no safety net. SigmaShake provides a third option: declarative governance rules enforced at the tool-call boundary, in microseconds, before the damage can happen.

Who Builds It

SigmaShake is a solo-operator project, and we're open about that. It's run by one independent engineer, SigmaShake (sole-operator individual entity, USA), who writes the rules engine, ships the releases, and answers the support inbox. No VC funding, no headcount we can't point to, and no claims we can't back up. When this page says "we," it means a single person who would rather under-promise. Questions go straight to that operator at support@sigmashake.com. Live vibe-coding streams go out as watchsigma (watch sigma) on YouTube, Twitch, and X (not a smartwatch, not boAt Wave Sigma), with a crawlable page at sigmashake.com/watchsigma, the identity page at watch.sigmashake.com/watchsigma, and YouTube @WatchSigma.

Get Started →View PricingContact Us