NiaShield AI Control Plane
Heavisideai · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 8 captures on record
What the publisher says
As described on Microsoft Marketplace.
NiaShield: Zero-Persistence AI Control Plane
Stop relying on vendor promises for data privacy. Demand cryptographic proof.
Show the rest of the publisher’s description (26 more lines)
NiaShield is the zero-persistence AI control plane designed specifically for regulated enterprises and federal contractors. Think of it as a Digital SCIF for your AI workloads: what enters is strictly controlled, what leaves is strictly controlled, and absolutely nothing lingers by accident.
How It Works
NiaShield deploys directly into your own Azure subscription as a single-tenant application. Whether you route your prompts to Azure OpenAI, Anthropic, Google, Mistral, or Aleph Alpha, NiaShield ensures your data is handled exclusively in volatile memory.
At the end of every single session, the system executes the SDIP-6 protocol to:
- Scrub the memory heap.
- Destroy the per-session encryption key.
- Emit a Certificate of Incineration (COI) directly into your Azure Log Analytics workspace.
The Certificate of Incineration (COI) is the exact artifact your contracting officer, auditor, or DPO needs. It is a fully self-contained JSON record carrying the session identifier, cryptographic timestamps, the destruction record, and a digital signature. It can be verified offline by anyone—with zero reliance on a Heaviside AI endpoint.
Why Architecture Beats Contracts
Federal AI procurement is rapidly moving toward GSAR 552.239-7001, requiring certified destruction of Government Data at session end. Simultaneously, the EU AI Act and GDPR Article 17 impose parallel burdens on European deployments.
Hosted, multi-tenant AI platforms cannot satisfy these clauses architecturally—they can only attest to them contractually. NiaShield satisfies these clauses by construction:
- No Vendor Data Plane: Heaviside AI has zero read-path to your prompts, responses, or upstream API keys.
- Customer-Controlled Keys: The signing key behind every COI lives exclusively in your Azure Key Vault. We never hold it.
NiaShield 5.6.1 Non-Repudiable Issuance
NiaShield ships with customer-resident Ed25519 signing keys linked to public-key publication through your Microsoft Entra Verified ID infrastructure. Proven on 7/7/2026
A federal CISO or 30(b)(6) deponent can verify any COI against a credential issued by your own identity provider. The standalone verifier ships with four modes (A, B, B-prime, and C) and can run entirely offline on a local machine.
Ideal For
- Federal Primes & GovCon: Operating under GSAR 552.239-7001.
- Legal (AmLaw 200 & Fortune 500): Managing strict privilege-review obligations.
- Healthcare & Life Sciences: Operating under HIPAA.
- Financial Services: Navigating GLBA, NYDFS, and state privacy acts.
- EU Enterprises & Public Sector: Complying with GDPR and the EU AI Act, completely its own product.
Frictionless Deployment
Launch via a one-click ARM template directly into your Azure subscription. Customer-managed everything: keys, telemetry, evidence archives, and audit trails.
Integration requires no rewrite—your existing SDKs and code remain exactly the same. At runtime, exactly two outbound calls exist, both resolving to endpoints you control.
Architecture covered by U.S. Provisional Patent Applications 64/042,610 (filed April 17, 2026) and 64/068,643 (filed May 18, 2026).
Preview
5 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Sources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.






