Aegis Console

// Runtime cloud security

Your cloud is telling you what it is doing. We are the part that listens.

Aegis Console watches identity, egress, syscalls and control-plane change across 1,840 production environments — and pages a human in a median of 38 seconds, with the rule, the evidence and the query attached. No risk score. No lock-in.

Watching production for

The platform

Six things it does, described in the terms an engineer would use

Not "AI-powered visibility". These are the mechanisms, and each one is documented to the point where you could argue with it.

  • Identity, not just configuration

    Every AssumeRole, token exchange and console login is scored against what that identity has actually done for the last ninety days — by source, by hour, by target.

  • Runtime, in the kernel

    An eBPF sensor on your nodes sees process execution, connection establishment and egress volume in under a second. No agent on anybody's laptop.

  • Correlation, not alert volume

    Related signals assemble into one situation with one page. The median customer gets eleven pages a week, not two hundred, and reads all of them.

  • Evidence attached, always

    Each situation carries the matched events in full, the ninety-day history that made them unusual, and the exact query that found them — copyable, re-runnable.

  • Detections in your repository

    412 patterns as YAML, synced from a Git repo you own. Fork them, edit them, review them like any other code. Leaving takes an afternoon, not a quarter.

  • Egress baselines per workload

    Each workload is compared against itself, per hour of week, learned over forty days. No thresholds to set, and none to raise when Black Friday arrives.

  • 4.1BEvents normalised every day, across three clouds
  • 1,840Production environments under continuous watch
  • 38sMedian event to phone ringing, measured end to end
  • 99.98%Ingest availability, trailing twelve months, unsampled

How it works

Three stages, and we publish the latency of each

The whole budget is in the 38-second post, including the eleven seconds that belong to AWS rather than to us.

01

Collect what actually happened

Cloud control-plane logs, identity provider events, network flow, and an eBPF sensor on your nodes. Read-only credentials, nine minutes to first event, no write access to anything.

  • AWS, GCP and Azure control planes
  • Kubernetes runtime via eBPF — 0.7% node CPU at p50
  • Okta, Entra ID, Google Workspace
  • VPC / VNet flow logs and DNS
Sources14 connected
aws-prod · CloudTrail
11.4s lag
aws-prod · EventBridge
0.9s lag
gke-research · eBPF
0.3s lag
entra-id · sign-in logs
6.2s lag
vpc-flow · eu-west-1
48s lag
02

Normalise, enrich, baseline

Everything becomes OCSF within four seconds. Identities are resolved to humans and pipelines, workloads to owners, and every principal to the set of things it could reach.

  • One schema across three clouds
  • Forty-day per-workload, per-hour behavioural baselines
  • IAM reach computed from your live policy graph
  • Copies land in your object store as they arrive
Baseline · svc-checkout40 days
p50
8.4 MB/min
p99
21.1 MB/min
observed now
344 MB/min
03

Correlate, then page a human

Signals hold in a window and assemble. When enough conditions match, one situation opens with everything attached — and you can watch it forming in the console before it pages.

  • 412 correlation patterns, all readable
  • Median 38 seconds from event to phone ringing
  • Partial matches visible as forming, not hidden
  • Slack, PagerDuty, Opsgenie, or webhook
Situation #4412forming
  1. Source ASN never seen for this identity02:11:23 · northwind-deploy-ci · AS9009
  2. Orientation call sequence matched02:11:31 · sts, s3:ListBuckets, s3:GetBucketPolicy
  3. Credential age exceeds policy02:11:31 · key created 412 days ago
  4. Successful write to protected bucketnot matched · condition 4 of 4

3 of 4 matched · paged at 02:11:44

Where we draw the line

Four things we will not do, including the profitable ones

A product is defined as much by its refusals as its features. These four are in the contract, not just the pitch.

  • No black-box risk score

    You get the pattern, the matched conditions, the evidence and the query. Sorting is by reach, novelty and motion — three facts you can each interrogate — not one number you cannot.

  • No agent on developer laptops

    We watch production runtime and cloud control planes. Endpoint detection on employee machines is a different product with a different consent model, and we do not sell it.

  • No data lock-in

    Detections are YAML in your Git repository. Normalised events stream to your own object storage in OCSF as they arrive. Cancel and you keep the history and the rules.

  • No seat tax on looking

    Responder seats are priced. Read-only access is unlimited on every plan, including Team. Charging engineers to look at their own security posture makes estates less safe.

Thirty minutes, your estate

We will show you the detections before you show us your cloud.

The demo starts with the 412 patterns open in a browser. If they do not describe threats you actually have, we would rather you found that out in the first ten minutes than the first quarter.