NiaShield AI Control Plane
Heavisideai · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 7 captures on record
What the publisher says
As described on Microsoft Marketplace.
NiaShield: Zero-Persistence AI Control Plane
Stop relying on vendor promises for data privacy. Demand cryptographic proof.
Show the rest of the publisher’s description (23 more lines)
NiaShield is the zero-persistence AI control plane built for regulated enterprises and federal contractors. Think of it as a Digital SCIF for your AI workloads: what enters is controlled, what leaves is controlled, and nothing lingers by accident.
How It Works
NiaShield 5.7.0 installs to your desktop and opens in its own window — nothing to deploy, nothing to configure. Whether you route prompts to Azure OpenAI, Anthropic, Google, or Groq, your data is handled exclusively in volatile memory.
At the end of every session, SDIP-6 scrubs the memory heap, destroys the per-session encryption key, and emits a Certificate of Incineration (COI).
The COI is the exact artifact your contracting officer, auditor, or DPO needs: a self-contained JSON record carrying the session identifier, cryptographic timestamps, the destruction record, and a digital signature. Anyone can verify it offline, with no reliance on a Heaviside AI endpoint.
Why Architecture Beats Contracts
Federal AI procurement is moving toward GSAR 552.239-7001, requiring certified destruction of Government Data at session end. The EU AI Act and GDPR Article 17 impose parallel burdens in Europe.
Hosted, multi-tenant AI platforms cannot satisfy these clauses architecturally — they can only attest to them contractually. NiaShield satisfies them by construction:
- No Content Retention: Prompts and responses are never written to a database, to disk, or to logs. Not a retention setting — a property of how the software is built.
- US Providers Only: The provider matrix is restricted to US-headquartered AI vendors at the binary level, not by administrative configuration.
- PII Stopped at the Door: Inputs are screened before transmission, with SSN and payment-card detection as a floor that cannot be disabled.
Non-Repudiable Issuance
Certificates are signed with Ed25519 keys and published for independent verification. Proven 7/7/2026. A federal CISO or 30(b)(6) deponent can verify any COI without trusting Heaviside AI. The standalone verifier runs entirely offline.
Ideal For
- Federal Primes & GovCon under GSAR 552.239-7001
- Legal (AmLaw 200 & Fortune 500) privilege review
- Healthcare & Life Sciences under HIPAA
- Financial Services under GLBA, NYDFS, and state privacy acts
- EU Enterprises & Public Sector under GDPR and the EU AI Act
Try It, Then Scale It
Start the free trial with up to 10 seats, sign in, and work. When you are ready for a single-tenant deployment inside your own Azure subscription — customer-managed keys, telemetry, evidence archives, audit trails — that edition is a separate offer.
Covered by U.S. Provisional Patent Applications 64/042,610 and 64/068,643.
Name (26) and summary (77) are both well inside their limits, so the description was almost certainly the one that tripped. If the error was actually on a different field, tell me which and what number it named.
Preview
2 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment · as of 2026-08-29
Plans and pricing as listed
1 listedSources
Publisher resources
1 linkLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.



