Findings ledger
Every verdict becomes a durable, idempotent row with evidence references and scorer version pinned for replay.
Security decisions with evidence attached.
AEGIS turns noisy findings into calibrated verdicts—grounded in scope, evidence, priors you own, and a ledger that never silently drops a decision.
Built for defenders who need automation without surrendering explainability. Every action stays inside owned-asset boundaries, every score can be replayed, and uncertainty remains visible.
Never silently drop
Criticality-aware bands
Versioned scorer
Thinness stays visible
Security teams receive more findings than they can investigate, while simple automation often hides the assumptions that make a verdict unsafe.
AEGIS is the decision layer between detection and action: it audits scope, gathers bounded evidence, combines it with calibrated priors, and records the result for later review.
Choose a finding class and watch the AEGIS pipeline make uncertainty, scope, evidence, and disposition visible in one control center.
GuardDuty: unusual AssumeRole activity on production account
Finding received with asset scope: prod-accounts/*
Finding received with asset scope: prod-accounts/*
Investigation in progress
The verdict card will appear after the evidence loop and ledger write are complete.
1 / 6 stages complete
AEGIS makes the invisible parts of security automation inspectable: scope, evidence quality, data thinness, model influence, and what happened after the verdict.
Every verdict becomes a durable, idempotent row with evidence references and scorer version pinned for replay.
Feedback separates two questions a single label conflates: was the detection correct, and did it warrant action. Thin data never masquerades as certainty.
Soft evidence is clamped; hard signals are explicit. The engine exposes the reasoning path without leaking thresholds.
HIGH, BOUNDARY and LOW come from your cost model, not ours: you set what a missed finding and a wasted hour are worth, and the thresholds follow per asset.
Closed findings re-enter a retest pool and the floor drifts, so activity shaped to sit just under the threshold cannot stay there. This is what makes auto-close defensible rather than merely quiet.
Findings that are individually low and jointly high are scored as a path, not a list. A chain that reaches a critical objective lifts every step in it.
Pre-tool hooks keep collection inside owned assets and allowlisted operations before evidence is gathered.
Playbooks, scoring, feedback, and explanation are exposed as composable tools for defender workflows.
SIEMs and cloud audit logs send findings in. Approved actions go back out as typed, scoped intents, and the connector that enforces them can run in your infrastructure holding your credentials, so keeping control is an architectural fact rather than a promise. A decision layer should not need god-mode keys to your identity plane.
A Pub/Sub forwarder deployed inside the customer project maps audit events to the intake contract. Running in production today.
Custom Manager Integrator sends structured alerts into the AEGIS webhook for host, FIM, vulnerability, and security monitoring.
Saved searches and alert actions feed correlated findings into the same normalized intake contract.
Alerting webhooks and forwarding adapters connect search-based detections to the evidence loop.
Logic Apps and automation rules route Microsoft security findings into AEGIS for calibrated disposition.
Wazuh path: use the open-source Manager Integrator with JSON alerts and an authenticated AEGIS webhook. Stable source IDs preserve deduplication and replay.
availableAWS EC2 security groups
plannedCrowdStrike Falcon · SentinelOne · Kubernetes NetworkPolicy
availableRedis token blacklist
plannedOkta · Microsoft Entra ID
availableAWS IAM
plannedMicrosoft Graph / Entra ID · Okta
availableCloudflare WAF · AWS WAFv2
plannedNetwork firewall and IP-set services
Approval is a grant, not a click per alert. A human authorises a class of action on a class of asset for a bounded window; each execution cites that grant, carries an idempotency key, and writes its provider result back to the ledger. Approving one action at a time does not survive volume: it produces consent fatigue and an audit trail that records agreement without attention.
AEGIS keeps the model in its lane. The engine owns the ledger, priors, scoring, and bands; hooks own scope; playbooks define the evidence workflow; MCP exposes the capability without making the model the source of truth.
raw signal
owned asset
bounded proof
feedback
log-odds
route
replay
Bring one noisy finding, one owned environment, and one decision you want to make safer. We will help scope an isolated pilot around it.
Pilot requests are reviewed manually. Please do not include secrets, credentials, or sensitive production data.