
The typical implementation process for Sigrid software involves several key steps and can vary in duration depending on the complexity and number of teams involved. Here is a detailed overview:
Technical Onboarding: This initial phase involves mapping your software portfolio visually in Sigrid and integrating the platform into your software development lifecycle. The technical onboarding is usually completed within 1 to 4 weeks.
Integration with Development Processes: Sigrid supports various development methodologies, including Agile and Scrum. It integrates seamlessly with your CI/CD pipeline, providing continuous feedback on code quality, security, and maintainability.
Setting Quality Objectives: During the onboarding, teams define quality objectives for non-functional aspects such as test code coverage and the state of open-source libraries. These objectives are monitored over time to ensure continuous improvement.
Continuous Monitoring and Feedback: Once integrated, Sigrid continuously monitors the software's health, providing insights into maintainability, security, architecture, and technical debt. This helps teams make informed decisions and prioritize critical initiatives.
Regular Updates and Support: Sigrid offers ongoing support and regular updates to ensure the platform remains aligned with the latest technologies and industry standards.
The overall implementation process is designed to be flexible and adaptable to the specific needs of each organization, ensuring a smooth transition and effective use of the platform.
Sigrid software can be customized to fit specific business needs. Here are some key points about its customization capabilities:
Configuration Files: Sigrid allows extensive customization through configuration files, specifically the Sigrid.yaml file. This file can be tailored to define custom components, exclude files, or adjust dependency settings as needed.
Scope Configuration: You can change Sigrid’s configuration for your project to make its feedback as useful and actionable as possible. This process, known as "scoping," involves setting up the analysis scope to focus on specific areas of interest.
Multi-Repo Support: Sigrid supports multi-repo systems, providing a unified architectural view across multiple projects or teams.
The additional costs associated with Sigrid software can include setup fees, maintenance, and support charges. Here are some details:
Setup Fees: The initial setup may involve costs related to technical onboarding and integration with your development processes. This phase typically takes 1 to 4 weeks.
Maintenance Costs: Ongoing maintenance costs can arise from continuous monitoring and updates to ensure the platform remains aligned with the latest technologies and industry standards.
Support Charges: Sigrid offers ongoing support, which may involve additional charges depending on the level of support required. This can include technical support, regular updates, and customization assistance.
Sigrid offers comprehensive training and support to help new users get the most out of the platform:
SIG Academy: The SIG Academy provides focused training programs on software quality management in Sigrid and the SIG methodology for software quality analysis. These courses are designed to help users understand Sigrid from top to bottom, improving their software quality and coding skills.
Documentation: Sigrid offers extensive documentation that acts as a user guide, covering everything from getting started to advanced usage scenarios. This includes roles and usage, analysis scenarios, and integration with development processes.
Ask Me Anything (AMA) Sessions: Sigrid hosts AMA sessions where users can get a comprehensive understanding of the platform, discover tips and tricks, and troubleshoot any issues.
Sigrid implements robust security measures to protect data:
Continuous Security Scanning: Sigrid continuously scans the software portfolio to uncover vulnerabilities in the source code and ranks risks by severity and impact. This helps in identifying and addressing potential security issues proactively.
AI-Powered Insights: The platform uses AI to provide detailed explanations and actionable mitigation advice tailored to each technology. This ensures that security measures are effective and up-to-date.
Customizable Security Goals: Sigrid allows organizations to set custom security objectives, ensuring that security efforts are aligned with business goals.
Multi-Standard Reporting: Sigrid supports multi-standard reporting capabilities, including OWASP, ISO, and CWE. This flexibility allows organizations to comply with various security standards and regulations.
Automatic Detection and Resolution: Sigrid uses a fingerprinting method to automatically detect and resolve security findings, reducing the amount of manual work required. This ensures that security issues are addressed promptly and efficiently.
Sigrid releases updates regularly to ensure the platform remains aligned with the latest technologies and industry standards. Here are some key points about their update process:
Continuous Improvement: Sigrid is continuously enriched with smart software insights and code analysis models. This means that updates are rolled out frequently to incorporate new features, improvements, and security enhancements.
Managed Updates: Updates are managed seamlessly to minimize disruption. The platform ensures that new features and improvements are integrated smoothly into the existing system.
Sigrid has clear policies regarding data ownership and portability to ensure client data is handled securely and responsibly:
Data Ownership: Clients retain full ownership of their data. Sigrid ensures that all client data remains under the control of the client, and no data is shared with external parties without explicit consent.
Data Portability: Sigrid supports data portability, allowing clients to export their data as needed. This ensures that clients can move their data to other systems or platforms if required.
Sigrid offers flexible terms for scaling up or down to accommodate changing organizational needs:
Flexible Licensing: Sigrid provides flexible licensing options that allow organizations to adjust their usage based on their current needs. This means you can scale up to include more systems or users as your organization grows or scale down if your requirements decrease.
Customizable Scope: The platform supports customizable scoping, enabling you to define the analysis scope to focus on specific areas of interest. This flexibility ensures that you can tailor the platform's capabilities to match your evolving needs.
The terms and conditions for contract renewal and cancellation for Sigrid are outlined in their Terms of Use and Confidentiality document:
Contract Renewal: Contracts are typically renewed automatically unless explicitly canceled by the client. The renewal terms are agreed upon in writing with SIG and are subject to the client's compliance with the applicable fees.
Cancellation: Clients can cancel their subscription by providing notice as specified in the contract. The cancellation terms include provisions for the termination of access to the Sigrid platform and the cessation of services.
Sigrid meets several globally recognized compliance standards to ensure high-quality software assurance:
ISO 25010: Sigrid's approach to software quality is based on the ISO 25010 standard for software product quality. This standard provides a comprehensive framework for evaluating software quality characteristics.
OWASP: Sigrid supports multi-standard reporting capabilities, including the OWASP (Open Web Application Security Project) standards, which focus on improving the security of software.
CWE: The platform also aligns with the Common Weakness Enumeration (CWE) standards, which provide a detailed list of software weaknesses and vulnerabilities.