Company

Build systems that can show their work.

Aegis starts with a concrete software-security problem today and is building toward a broader trust layer for software and AI agents. The company thesis is simple: security-sensitive autonomy needs evidence, permission, independent verification, policy, recovery, and memory.

CURRENT PRODUCT

A real product, already shipping.

Version 0.2.4 ships across VS Code, the local Aegis runtime, and GitHub Action workflows. The current packaged runtime target is Linux x64.

MARKET ENTRY

Start where the risk is already real.

Aegis is entering through verified security-sensitive software changes rather than asking customers to buy the entire long-term agent-trust vision on day one.

OPERATING MODEL

Public developer surface, selective commercial layer.

Community provides the public developer entry point. Founding Pro adds the paid verification workflow, while team and enterprise requirements are evaluated directly rather than presented as finished self-serve controls.

Software agents and automated systems are moving from suggestion toward execution: reading repositories, changing files, invoking tools, running commands, opening pull requests, and participating in longer development tasks. That shift creates a new trust question around software changes and, eventually, around software-agent actions themselves.

The company starts with a concrete trust problem

The security stack cannot stop at “a scanner found something” or “a model says the patch looks good.” Security-sensitive automation needs a chain that keeps evidence, authorization, remediation, verification, policy, and memory distinct.

The thesis is broader than one product surface

If software agents become a normal production actor, organizations will need infrastructure that can establish which actions were permitted, what evidence supported them, whether the result was independently verified, and what should be remembered or recovered afterward.

A model is an input, not an authority.

No single model should be able to propose a security-sensitive action and serve as the sole proof that the action was correct.

Capability is not permission.

The fact that software can inspect, execute, modify, or connect does not mean the current task authorizes it.

Recovery belongs in the trust model.

Autonomous systems will fail. Useful infrastructure preserves enough state and evidence to understand what happened and support a safe recovery path.

Public claims should age well.

Aegis does not publish invented customers, adoption metrics, performance claims, compliance badges, or unshipped product capabilities as if they already exist.

Working on a problem where trust has to be proven?

Talk to Aegis about Founding Pro, a team evaluation, research collaboration, or a company conversation.

Contact Aegis