Frontier-grade Claude models with agentic workflows, strong coding, and enterprise guardrails delivered via developer console, web app, and cloud partners.
Aegis
About Aegis
Aegis is a trust infrastructure tool for software and AI agents that independently verifies security claims by separating findings from evidence, authorization, and verification. It operates within VS Code as an extension, allowing developers to scan code locally without requiring a website account for basic use. The tool maps attack paths, connects findings to supporting evidence, and maintains an inspectable workflow from mapping to decision-making. It distinguishes between claims, evidence, and decisions, ensuring that security conclusions are not conflated with unverified scanner outputs. Aegis provides a local-first workflow for individual developers and offers advanced verification capabilities for professionals through its Founding Pro plan. The tool also includes a browser-local snapshot feature for quick, privacy-preserving previews of review surfaces without executing code or uploading data.
Key features
- Local VS Code extension for code scanning
- Attack Graph and Data Sentinel for mapping attack paths
- Threat Model for connecting assets and trust boundaries
- Secure Fix workflow for reviewing proposed changes
- Fix & Prove capabilities for verifying remediation
- Browser-local snapshot for privacy-preserving previews
- GitHub sign-in for billing identity linking
- Task planning and deeper trusted analysis in Founding Pro
Use cases
- Verifying security-sensitive code changes before deployment
- Reviewing AI-generated code patches for trustworthiness
- Conducting privacy-preserving code audits via snapshot
Pros
- Separates security claims from evidence to avoid conflating findings with verdicts
- Operates locally within VS Code without mandatory web account creation
- Provides inspectable workflow stages from mapping to decision-making
- Offers a browser-local snapshot for privacy-preserving previews
- Supports both individual developers and professional teams with tiered plans
Cons
- Advanced verification features require a paid subscription
- Team and Enterprise plans require direct contact for setup
- Snapshot feature does not provide full verification or verdicts
- No free web account is required for Community tier, but advanced features are paid
Frequently asked questions about Aegis
What is Aegis and what does it do?
Aegis is a trust infrastructure tool for software and AI agents that independently verifies security claims by separating findings from evidence, authorization, and verification. It operates as a VS Code extension, allowing developers to scan code locally without requiring a website account for basic use.
Who should use Aegis?
Aegis is designed for developers, security professionals, and teams who need to verify security-sensitive software changes and maintain an inspectable workflow from mapping to decision-making. It suits those who require evidence-based trust rather than unverified scanner outputs.
How does Aegis work?
Aegis works by mapping attack paths, connecting findings to supporting evidence, and maintaining a workflow that includes claim, evidence, authorization, verification, and decision stages. It provides a local-first workflow for individual developers and advanced verification capabilities for professionals.
Does Aegis require a website account to use?
No, the Community plan does not require a website account to start using Aegis. A GitHub sign-in is only needed to link billing identity for paid access.
What is Aegis Snapshot and how does it work?
Aegis Snapshot is a browser-local feature that provides a privacy-preserving preview of review surfaces without executing code or uploading data. It surfaces deterministic review signals for the first thirty seconds of evaluation but does not issue a security verdict or replace full Aegis verification.
What are the key stages in Aegis' workflow?
The key stages in Aegis' workflow include mapping attack paths, reasoning in repository context, reviewing changes, proving fixes, making decisions, and maintaining control. Each stage is designed to keep the process inspectable and evidence-based.