Everyone else scores your posture.
We prove your records.
A live cyber-threat-intelligence cockpit fused with a sealed forensic vault: every finding, incident and decision can be hashed, chained and anchored to a public ledger — so your evidence is checkable by an auditor, a regulator or an insurer without trusting us.
One cockpit: the threat picture and the proof, together
Security tools tell you what is happening. Compliance tools ask you to trust their audit trail. Sealgenic does both jobs in one screen — and makes the record independently checkable.
Threat feeds that need no setup
CISA KEV, FIRST EPSS exploit prediction, ransomware leak-site monitoring, live IOC streams and ICS advisories — streaming on day one, no credentials required. Connect your own estate (Defender, Pentera, Qualys, Vectra, Varonis, KnowBe4 and more) when you are ready.
The Sovereign Vault
Findings, incident actions and reports are hashed in the browser, chained to the record before them, and anchored through our gateway to a public ledger. Alter any sealed record afterwards and the chain visibly breaks — provably, not rhetorically.
An ExCo view directors actually read
No jargon, no vanity scores. Coverage per binding obligation, the top risks each with an owner and a decision, and the one artefact no competitor offers: records a board can state are independently verifiable.
Real capture of the vault engine sealing files. Licence details redacted — because that is the kind of thing we redact.
Web, desktop, workforce
- Web cockpit — nothing to install
- Standalone desktop app — the cockpit plus a local file-integrity watcher that seals Annex IV certificates as files change
- Secure Workspace — for every employee: a logged, sealed AI assistant and a one-press Panic Button that reports compromise and can trigger account lockdown
Open Channel
When you lock a compromised account, you also cut off the person behind it. Open Channel is an end-to-end encrypted line to a locked-out employee — the server relays ciphertext it cannot read, every message is chained, and the conversation exports as a self-verifying evidence pack.
Immutable offsite copies
Optionally replicate every sealed certificate and file to object-locked cloud storage with multi-year retention — write once, read many, enforced by the storage layer itself. A daily custody heartbeat re-reads the archive and anchors proof that it is intact.
Connect Microsoft Defender & Entra — read your live security picture, act when it matters
Register one application in your Microsoft tenant and Sealgenic reads your live security signal and, on your command, closes the door on a compromised account. Least-privilege by default; every lockdown is a deliberate, permissioned action — never automatic.
Your live security picture, in the cockpit
Sealgenic authenticates to Microsoft Graph as your own registered app and reads Defender incidents and alerts, device-management state, and your directory — surfaced alongside the external threat feeds. Read-only permissions; nothing is written to your tenant unless you explicitly act.
Disable the account, revoke the sessions
When an employee is compromised, the Secure Workspace Panic Button disables the account in Entra and revokes its active sessions through Graph — cutting off an attacker who already has a live session. The action is sealed as an incident record the moment it fires.
Every step is evidence
Connecting, reading and locking down all produce tamper-evident records: who acted, on which account, at what time, hash-chained and anchored. The response and the proof of it are the same artefact.
What "connect your estate" honestly means
- You stay in control of the keys.
- You create the app registration in your own tenant and grant exactly the permissions you choose. Revoke consent and the connection stops — Sealgenic holds no standing access you cannot withdraw.
- Lockdown is permissioned and bounded.
- Account-disable and session-revoke require an explicit directory-write permission you grant deliberately, and Microsoft will not let the app disable an account with equal or higher privilege than itself. It is a scalpel, not a kill switch.
- It reads what's there — no more.
- If a Defender workload has not been provisioned in your tenant, the panel honestly shows nothing rather than inventing findings. Connected means connected; empty means empty.
How sealing works — five steps, no black box
The whole mechanism fits in one screen, because a proof you cannot explain is not a proof.
The record is hashed where it is created
A SHA-256 digest is computed in your browser or on your machine — content
can stay with you; the fingerprint is what travels.
Each record is chained to the one before
Every entry carries the previous entry's hash. Change anything in the past and every later link visibly fails verification.
The chain head is anchored to a public ledger
Checkpoints are written to a public Hedera Consensus Service topic — a record we do not control and cannot rewrite, timestamped by network consensus.
Anyone can verify, without trusting us
An auditor re-computes the hashes from your records and compares the anchored value on a public explorer. No Sealgenic software or goodwill required.
Privacy survives the proof
Erasure requests destroy content while keeping the cryptographic commitment — the chain still verifies, the fact a record existed remains provable, the data itself is gone.
Evidence for the obligations that actually bind you
Sealgenic produces and protects evidence. It does not hand out certificates — no honest tool can — and it tells you which framework language it genuinely supports.
| Regime | What Sealgenic contributes |
|---|---|
| PCI DSS v4.0.1 | Tamper-evident audit-trail protection and file-integrity evidence mapping to requirements such as 10.3.4 and 11.5.2, and a sealed record of the incident-response process behind 12.10. |
| POPIA (South Africa) | Security-safeguard evidence (s19), operator-notification records (s21) and a provable trail of security-compromise notifications (s22). |
| King IV / King V | Technology-and-information governance evidence a board can table — with the applicable code confirmed against your financial year, not guessed. |
| EU AI Act | A tamper-evident record of workforce AI usage that supports deployer log-retention and record-keeping duties. It does not itself constitute a high-risk system's built-in logging, and we say so. |
| NIS-2 / DORA | Structured incident-reporting workflows and sealed report trails for entities these EU regimes actually bind — clearly labelled as not applicable where they do not. |
What we deliberately do not claim
- "Sealgenic makes you compliant."
- No. It authenticates records. Compliance is an organisational status only you can hold — our job is to make your evidence undeniable.
- "Sealgenic prevents fines."
- It produces proof; it prevents nothing. Proof is what changes the conversation with a regulator, an auditor or an insurer.
- "The ledger proves who did it."
- Actor attribution is circumstantial process evidence, not cryptographic proof of authorship — and any vendor telling you otherwise is overselling.
- "Anchoring is permanent today."
- Current builds anchor to a public test network: real, timestamped and independently checkable now, with production-network anchoring as the enterprise upgrade path.