Trust & Security
How Aegis is designed to protect you — and what we do not claim.
Security products earn trust through design choices you can inspect, not through badges. Here is how Aegis is built.
Security design principles
Built in, not bolted on
Zero-trust by design
Every request is authenticated and authorised on its own merits. Network location grants nothing.
Default-deny RBAC
Roles start with no permissions. Access to view evidence and to execute actions is granted explicitly and separately.
Tenant isolation
Tenant boundaries are enforced server-side on every request, never by the client.
Complete audit trail
Approvals, actions, evidence access and exports are recorded with who, what and when.
MFA via your identity provider
Sign-in is delegated to your IdP, so your MFA and access policies apply to Aegis.
No client-side secrets
Credentials and keys never ship to the browser. Sensitive operations are performed server-side.
Outbound-only edge
The customer-edge service connects outbound only. There is no inbound administrative access to your environment.
What we claim
Plainly stated
We do not claim independent certifications or third-party audits on this site. We do not publish customer names, testimonials or statistics we cannot substantiate.
Assurance documentation — including architecture detail, data-flow descriptions and our security practices — is available on request under appropriate confidentiality.
See exactly what Aegis does when something goes wrong.
We will walk your team through an incident from first signal to verified outcome. You will see what Aegis observed, what it inferred, what it proposed and what actually happened.