Passive digital checks
Observe TLS, headers, DNS, cookies, CORS, and related posture without active probing or disruption.
Aegis turns authorized digital, physical-privacy, and supply-chain observations into a calm view you can inspect, challenge, and act on — without overstating what was not measured.
Purposeful workflows keep the operator close to the source, the authorization, and the exact limits of each result.
Observe TLS, headers, DNS, cookies, CORS, and related posture without active probing or disruption.
Run a guided, authorized inspection where confidence and coverage remain separate from severity.
Choose, drop, paste, and preview bounded UTF-8 OpenAPI, SARIF, CycloneDX, and SPDX documents locally.
Trace findings to their source, preserve provenance, and export artifacts a human can inspect.
Register the target and affirm the legal right to inspect it. Aegis fails closed when the scope is unclear.
Every result carries evidence, method, severity, confidence, and an honest coverage note.
Use a clear report, history, and export trail to review and act. Aegis prepares; it never silently decides for you.
Aegis is an authorized-only, local-first security product. Current token access is administrator-provisioned for a private instance; self-service signup, recovery, and public multi-tenant identity are not activated.
Authorized-only · evidence-based · point-in-time — Aegis cannot guarantee the absence of weaknesses or hidden devices. On this machine, live external HTTP/TLS may be network-blocked and shown as an honest coverage gap. Severity and confidence are kept separate. Assessments stay in this process until it restarts. A theme choice may persist in this browser. Findings are not written to disk unless you export them.