Architecture

A control plane that never reaches in.

Customer-edge services run inside your perimeter and connect outbound only. The control plane coordinates policy, cases and approvals — it holds no inbound administrative access to your environment.

Topology

Control plane and customer edge

Aegis architecture: outbound-only customer edgeThree customer sites each run an Aegis edge service beside their local telemetry and evidence store. Each edge service opens an outbound-only TLS connection on port 443 to the Aegis control plane; the control plane has no inbound path into any site. Site C also contains an isolated deception segment, deployed and monitored by its local edge service, with no direct connection to the control plane.CUSTOMER SITE A · YOUR PERIMETERTelemetry & raw logsEvidence stays localAegis edge serviceOUTBOUND ONLY · TLS 443CUSTOMER SITE B · YOUR PERIMETERTelemetry & raw logsEvidence stays localAegis edge serviceOUTBOUND ONLY · TLS 443CUSTOMER SITE C · YOUR PERIMETERTelemetry & raw logsEvidence stays localAegis edge serviceOUTBOUND ONLY · TLS 443Deception segment · isolatedDecoy services and credentials, deployed by the edge serviceAEGIS CONTROL PLANEPolicy & approvalsIncident metadata & casesVersioned API · /api/v1No inbound access into customer sites
  • Outbound-only connection initiated by the edge (TLS 443)
  • Local, inside your perimeter
  • Isolated decoy segment, managed by the edge

Responsibilities

Who does what, and where

  • Aegis control plane

    Coordination and governance

    • Policy, autonomy levels and approval workflows
    • Incident cases built from metadata
    • Reporting, tenant administration and audit trail
    • Versioned API contracts under /api/v1
  • Customer edge

    Collection, evidence and execution

    • Adapters to your existing security and IT tools
    • Raw telemetry and evidence retained locally
    • Approved actions executed with the credentials you grant
    • Deployment and monitoring of isolated decoys

Design principles

Constraints we build to

  • Outbound only

    The edge initiates every connection to the control plane over TLS on port 443. No inbound ports need to be opened.

  • No inbound admin access

    Neither the control plane nor Pythology staff hold standing inbound administrative access to customer systems.

  • Replaceable adapters

    Integrations sit behind an adapter layer, so a tool can be swapped without changing how Aegis reasons about evidence.

  • Versioned API contracts

    Edge and control plane communicate through versioned contracts (/api/v1), so components can be upgraded independently.

  • Server-side tenant isolation

    Tenant boundaries are enforced on the server for every request — never left to the client.

  • Viewing is not acting

    Permission to view evidence is separate from permission to execute actions, and each is granted explicitly.

Walk through the architecture with our engineers.

We can review how the edge would sit in your network, what it needs and what it never needs.