Pythology Aegis · Sovereign defence. Visible decisions.

Your infrastructure. Your intelligence. Your control.

Autonomous threat detection, investigation and governed response — designed to operate within your own security perimeter.

Or explore the interactive demonstration
Aegis architecture: outbound-only customer edgeThree customer sites each run an Aegis edge service beside their local telemetry and evidence store. Each edge service opens an outbound-only TLS connection on port 443 to the Aegis control plane; the control plane has no inbound path into any site. Site C also contains an isolated deception segment, deployed and monitored by its local edge service, with no direct connection to the control plane.CUSTOMER SITE A · YOUR PERIMETERTelemetry & raw logsEvidence stays localAegis edge serviceOUTBOUND ONLY · TLS 443CUSTOMER SITE B · YOUR PERIMETERTelemetry & raw logsEvidence stays localAegis edge serviceOUTBOUND ONLY · TLS 443CUSTOMER SITE C · YOUR PERIMETERTelemetry & raw logsEvidence stays localAegis edge serviceOUTBOUND ONLY · TLS 443Deception segment · isolatedDecoy services and credentials, deployed by the edge serviceAEGIS CONTROL PLANEPolicy & approvalsIncident metadata & casesVersioned API · /api/v1No inbound access into customer sites
  • Outbound-only connection initiated by the edge (TLS 443)
  • Local, inside your perimeter
  • Isolated decoy segment, managed by the edge

The lifecycle

Seven steps. Every one evidenced.

From first signal to verified outcome, Aegis records what it saw, what it concluded, what it proposed and what it did — so your team can follow the reasoning, not just the result.

  1. 01

    Detect

    OBSERVED
  2. 02

    Correlate

    INFERRED
  3. 03

    Investigate

    OBSERVEDINFERRED
  4. 04

    Authorise

    PROPOSED
  5. 05

    Respond

    EXECUTED
  6. 06

    Verify

    VERIFIED
  7. 07

    Learn

    PROPOSED

How each step works

Intelligence that shows its working

Every statement carries its claim state.

Aegis never blurs the line between evidence and interpretation. AI inferences are always labelled as inferences, with confidence — never presented as fact.

  • OBSERVED

    Directly seen in source telemetry or evidence. Carries its origin and integrity hash.

  • INFERRED

    A conclusion drawn by analysis or AI, shown with confidence. Never presented as fact.

  • PROPOSED

    A recommended action with scope and rollback, awaiting authorisation under policy.

  • EXECUTED

    An action that has been carried out, with who or what performed it and when.

  • VERIFIED

    An outcome confirmed by an independent check, separate from the executor.

Governed autonomy

You decide how far automation goes.

Autonomy is set by policy, per action class and per environment. Start at observation and expand only when the evidence gives you confidence.

  1. Level 0: Observe

    Aegis detects and records. No investigation or action is taken automatically.

  2. Level 1: Investigate

    Aegis gathers context and builds hypotheses. Every response is proposed for human approval.

  3. Level 2: Controlled autonomy

    Pre-approved, reversible actions within a defined scope may run automatically. Everything else needs approval.

  4. Level 3: Expanded autonomy

    Broader automatic response for explicitly authorised action classes, with verification and rollback enforced.

Data sovereignty

Your evidence stays where it belongs.

The customer-edge service runs inside your perimeter and connects outbound only. By default, raw logs and evidence never leave it.

  • Raw data stays local

    Telemetry and evidence are retained within your perimeter. The control plane works with metadata by default.

  • Outbound-only edge

    No inbound administrative access to your environment. The edge initiates every connection over TLS 443.

  • Approved, audited exports

    Anything that leaves your perimeter requires approval and is recorded in the audit trail.

Read the sovereignty model

Deception network

An early signal of intent.

Isolated decoy services and credentials, deployed by the edge service within segments you control. No legitimate user should ever touch them — so any interaction is worth investigating.

  • Isolated decoys

    Decoy services sit in dedicated, isolated segments, separated from production systems.

  • Planted credentials

    Credentials that should never be used. Their use is observed, recorded and linked to incidents.

  • Honest attribution

    IP-derived location is approximate at best and never treated as fact.

Explore the deception network

See exactly what Aegis does when something goes wrong.

We will walk your team through an incident from first signal to verified outcome. You will see what Aegis observed, what it inferred, what it proposed and what actually happened.