Inline, pre-execution enforcement
Aegis inspects request and response tool-call JSON before the agent can execute it. Denied userspace calls return HTTP 403.
SECURITY & TRUST
Aegis is security-ready software with evidence customers can inspect. It is not a substitute for an independent compliance audit, and we do not represent an evaluation as a certification.
Aegis inspects request and response tool-call JSON before the agent can execute it. Denied userspace calls return HTTP 403.
Signed decision records, hash-chain fields, warrant identifiers, and live-fire results make the security decision reviewable rather than a marketing score.
Allowlist, verified-role RBAC, sequence, intent, HITL, signatures, and flow/taint controls can be combined per workload.
A supported Aegis Node can enforce intent-bound syscall warrants with EPERM. Docker Desktop remains userspace-only.
Aegis currently makes no claim of SOC 2, ISO 27001, ISO 42001, FedRAMP, HIPAA, or FIPS 140 certification. Customers can review the control mapping and evaluation evidence, then apply their own governance and risk decision.
Start the sidecar, then launch the existing process through the wrapper. No SDK edits are required for supported SDKs; the agent keeps its vendor key.
Windows: attach.bat support-bot -- python your_agent.py
macOS/Linux: ./attach.sh support-bot -- python your_agent.pyRaw HTTP clients and programs that bypass the configured proxy are not protected by userspace inspection. Verify routing before making a security claim.