A finding is not a verdict.
Security conclusions stay distinct from the evidence that supports them.
Trust cannot be another model output.
Today, Aegis independently verifies security-sensitive software changes: what was claimed, what evidence supports it, what was authorized, and whether the resulting change actually held.
code --install-extension aegis-security.aegis-security
The trust problem
AI can propose changes and software can increasingly act without a human writing every line. That makes a security answer less important than the chain behind it: evidence, authorization, independent verification, and an explicit decision.
Security conclusions stay distinct from the evidence that supports them.
A proposed change does not get to certify that it solved the problem it addressed.
Uncertainty remains visible instead of being flattened into a clean-looking answer.
How Aegis works
Aegis keeps the security claim separate from the evidence used to support it. A finding does not become a verdict just because a scanner or model produced it.
Product proof
The shipped product keeps the security claim, supporting evidence, authorization state, remediation lifecycle, and verification outcome available for inspection instead of compressing trust into a single score.
Developer surfaces
VS Code, the GitHub Action, and the CLI/local runtime expose the same underlying separation between analysis, evidence, authorization, verification, and decision.
Review security findings, evidence, verification, policy, and remediation state inside the development loop.
Install Aegis → 02 / GITHUB ACTIONUse the public integration surface to preserve machine-readable verification artifacts around software changes.
Developer details → 03 / CLI + RUNTIMERun supported deterministic workflows through the local runtime. Current packaged target: Linux x64.
Installation details →Built for trust
Aegis separates analysis from permission, a proposed fix from post-change verification, and a billing redirect from actual paid authorization.
Security at Aegis →Supported deterministic analysis, evidence, policy, and security state can remain on the developer machine by default.
Security-sensitive execution and mutation are treated as separate capabilities rather than implied by analysis.
A proposed result is not trusted merely because the component that created it says it is correct.
Founding Pro authorization comes from signed, server-side billing state rather than a client-controlled success screen.
Today and direction
The product and the long-term thesis are related, but they are not presented as the same thing.
Aegis gives developers an inspectable path from security claim and evidence through authorized validation, remediation, and independent verification.
As software takes more actions on its own, Aegis is being built toward the same core questions at a wider scope: what happened, was it authorized, what proves the result, and should it be trusted?
Pricing
Start with Community. Founding Pro is $19/month. Team is $49 per active contributor with direct setup, and Enterprise is scoped with the organization.
For individual developers using the local-first Aegis workflow.
For professional developers who want the shipped paid verification and remediation capabilities.
For engineering teams that want Aegis across a shared development workflow. Team is $49 per active contributor, with setup handled directly by Aegis at launch.
For organizations evaluating private deployment, governance, and deeper security integrations.
AEGIS
Install Aegis, open a project, and inspect the evidence yourself.