Trust & Security

How Aegis is designed to protect you — and what we do not claim.

Security products earn trust through design choices you can inspect, not through badges. Here is how Aegis is built.

Security design principles

Built in, not bolted on

  • Zero-trust by design

    Every request is authenticated and authorised on its own merits. Network location grants nothing.

  • Default-deny RBAC

    Roles start with no permissions. Access to view evidence and to execute actions is granted explicitly and separately.

  • Tenant isolation

    Tenant boundaries are enforced server-side on every request, never by the client.

  • Complete audit trail

    Approvals, actions, evidence access and exports are recorded with who, what and when.

  • MFA via your identity provider

    Sign-in is delegated to your IdP, so your MFA and access policies apply to Aegis.

  • No client-side secrets

    Credentials and keys never ship to the browser. Sensitive operations are performed server-side.

  • Outbound-only edge

    The customer-edge service connects outbound only. There is no inbound administrative access to your environment.

What we claim

Plainly stated

We do not claim independent certifications or third-party audits on this site. We do not publish customer names, testimonials or statistics we cannot substantiate.

Assurance documentation — including architecture detail, data-flow descriptions and our security practices — is available on request under appropriate confidentiality.

See exactly what Aegis does when something goes wrong.

We will walk your team through an incident from first signal to verified outcome. You will see what Aegis observed, what it inferred, what it proposed and what actually happened.