Pythology Aegis · Sovereign defence. Visible decisions.
Your infrastructure. Your intelligence. Your control.
Autonomous threat detection, investigation and governed response — designed to operate within your own security perimeter.
Or explore the interactive demonstration- Outbound-only connection initiated by the edge (TLS 443)
- Local, inside your perimeter
- Isolated decoy segment, managed by the edge
The lifecycle
Seven steps. Every one evidenced.
From first signal to verified outcome, Aegis records what it saw, what it concluded, what it proposed and what it did — so your team can follow the reasoning, not just the result.
- 01
Detect
OBSERVED - 02
Correlate
INFERRED - 03
Investigate
OBSERVEDINFERRED - 04
Authorise
PROPOSED - 05
Respond
EXECUTED - 06
Verify
VERIFIED - 07
Learn
PROPOSED
Intelligence that shows its working
Every statement carries its claim state.
Aegis never blurs the line between evidence and interpretation. AI inferences are always labelled as inferences, with confidence — never presented as fact.
- OBSERVED
Directly seen in source telemetry or evidence. Carries its origin and integrity hash.
- INFERRED
A conclusion drawn by analysis or AI, shown with confidence. Never presented as fact.
- PROPOSED
A recommended action with scope and rollback, awaiting authorisation under policy.
- EXECUTED
An action that has been carried out, with who or what performed it and when.
- VERIFIED
An outcome confirmed by an independent check, separate from the executor.
Governed autonomy
You decide how far automation goes.
Autonomy is set by policy, per action class and per environment. Start at observation and expand only when the evidence gives you confidence.
Level 0: Observe
Aegis detects and records. No investigation or action is taken automatically.
Level 1: Investigate
Aegis gathers context and builds hypotheses. Every response is proposed for human approval.
Level 2: Controlled autonomy
Pre-approved, reversible actions within a defined scope may run automatically. Everything else needs approval.
Level 3: Expanded autonomy
Broader automatic response for explicitly authorised action classes, with verification and rollback enforced.
Data sovereignty
Your evidence stays where it belongs.
The customer-edge service runs inside your perimeter and connects outbound only. By default, raw logs and evidence never leave it.
Raw data stays local
Telemetry and evidence are retained within your perimeter. The control plane works with metadata by default.
Outbound-only edge
No inbound administrative access to your environment. The edge initiates every connection over TLS 443.
Approved, audited exports
Anything that leaves your perimeter requires approval and is recorded in the audit trail.
Deception network
An early signal of intent.
Isolated decoy services and credentials, deployed by the edge service within segments you control. No legitimate user should ever touch them — so any interaction is worth investigating.
Isolated decoys
Decoy services sit in dedicated, isolated segments, separated from production systems.
Planted credentials
Credentials that should never be used. Their use is observed, recorded and linked to incidents.
Honest attribution
IP-derived location is approximate at best and never treated as fact.
See exactly what Aegis does when something goes wrong.
We will walk your team through an incident from first signal to verified outcome. You will see what Aegis observed, what it inferred, what it proposed and what actually happened.