Architecture
A control plane that never reaches in.
Customer-edge services run inside your perimeter and connect outbound only. The control plane coordinates policy, cases and approvals — it holds no inbound administrative access to your environment.
Topology
Control plane and customer edge
- Outbound-only connection initiated by the edge (TLS 443)
- Local, inside your perimeter
- Isolated decoy segment, managed by the edge
Responsibilities
Who does what, and where
Coordination and governance
- Policy, autonomy levels and approval workflows
- Incident cases built from metadata
- Reporting, tenant administration and audit trail
- Versioned API contracts under /api/v1
Collection, evidence and execution
- Adapters to your existing security and IT tools
- Raw telemetry and evidence retained locally
- Approved actions executed with the credentials you grant
- Deployment and monitoring of isolated decoys
Design principles
Constraints we build to
Outbound only
The edge initiates every connection to the control plane over TLS on port 443. No inbound ports need to be opened.
No inbound admin access
Neither the control plane nor Pythology staff hold standing inbound administrative access to customer systems.
Replaceable adapters
Integrations sit behind an adapter layer, so a tool can be swapped without changing how Aegis reasons about evidence.
Versioned API contracts
Edge and control plane communicate through versioned contracts (/api/v1), so components can be upgraded independently.
Server-side tenant isolation
Tenant boundaries are enforced on the server for every request — never left to the client.
Viewing is not acting
Permission to view evidence is separate from permission to execute actions, and each is granted explicitly.
Walk through the architecture with our engineers.
We can review how the edge would sit in your network, what it needs and what it never needs.