Does T-Sigma run in our own AWS account, or is data sent to a third-party environment?
T-Sigma is customer-deployed — every component, including AI inference, runs entirely inside your own AWS account and VPC. Your data never leaves your tenancy.
How is this different from a services firm just adding more manual QA headcount?
T-Sigma's approach starts at the requirement, not the release — Knowledge Base captures every product requirement into a living graph, and Testing Studio generates and executes tests against that structured knowledge, so coverage evolves with the requirement instead of being re-built manually every cycle.
Does Ticking Minds hold standing access to our production data?
No — T-Sigma runs entirely inside your AWS account, and the security model is built so Ticking Minds holds no standing access to your production data.
What regions does T-Sigma currently support?
India and US AWS regions are supported today; additional regions are scoped on request as part of technical scoping.
What does the reference architecture look like end-to-end?
T-Sigma runs as a set of independently-scaled services inside your AWS account, with a managed identity layer, an AI reasoning layer, and encrypted data storage — all behind your own account boundary. We walk technical and security teams through the full reference architecture directly — reach out to set that up.
What's the teardown process if we want to remove T-Sigma from our AWS account?
A documented teardown script is provided to fully remove all deployed resources at engagement end.
Does Attest certification test against live production systems or only synthetic data?
Testing runs exclusively against a scoped, time-boxed sandbox endpoint using synthetic data — never production — with every irreversible action routed to a mocked tool layer.
Can an agent still get certified if it fails a safety check but performs well otherwise?
No — any Tier-2 (safety) dimension failure caps the overall verdict at Conditional, regardless of task-success score. A capable agent that can be manipulated into an unauthorized action does not pass on capability alone.
What's the IAM and key-management model inside our AWS account?
Least-privilege IAM roles are the default, with no shared credentials, and a documented, least-privilege IAM role set is provided ahead of deployment specifically for your security team's review and approval before anything is installed.
What's the documented IAM role set we'd need to approve before deployment?
It's provided as part of the pre-deployment package precisely so your security team can review scope before sign-off — nothing is installed without that approval.
What's covered under T-Sigma's encryption and audit posture?
Encryption key management, least-privilege access enforcement, and a full audit trail across every layer of the deployment, alongside alarms on error rate, latency, and resource health. We detail the specific AWS services involved directly with prospects and reviewers.