Other scanners tell you what's broken. Aegis fixes it.
Aegis scans your Windows and Active Directory estate, groups the findings into the attack paths an adversary would actually walk, and identifies the single fix that collapses the most of them. Then it applies that fix across your environment, on your approval, with a rollback for every change.
No sales call required. We'll email you once, when early access opens.
Nobody has a scanning problem. Everybody has a remediation problem.
Most organisations already know what is wrong with their environment. There is a scanner. There is a report. There is a spreadsheet with four thousand rows, sorted by severity score, that has been circulating between IT and security since the last audit.
What is missing is not detection. It is the work of actually closing things: the change requests, the maintenance windows, the testing, the internal negotiation over whose service breaks if legacy protocols are disabled. That work is manual, it is slow, and it is where the exposure lives. Scanning is continuous; remediation runs at the speed of change control.
Worse, the list is sorted wrong. A severity score rates a vulnerability in isolation, and adversaries do not attack in isolation. They chain a medium into a high into domain compromise. Ranking by score means working hard on findings that were never on the path.
Scan. Prioritise. Remediate.
Configuration state, continuously
A lightweight agent runs on your Windows endpoints and servers, collecting protocol and signing settings, OS currency, privilege and delegation relationships, and the misconfigurations that make internal compromise routine. No appliance, no credentialed network sweep.
Findings become chains
Findings are correlated into the sequences an adversary would use to move from an unprivileged foothold to domain control. Aegis then identifies the chokepoint: the one change that severs the most chains for the least disruption.
Approved, applied, verified
The change is presented as a plan: hosts in scope, settings modified, expected impact, rollback path. You approve it. The agents apply it. Aegis re-scans to confirm the finding is genuinely closed.
Automated security scanners find four thousand vulnerabilities. An adversary only needs three.
Your scanner gives you a tome of remediation steps. We automate it for you.
One fix that breaks four attack paths beats forty patches that break none.
Remediation cycles measured in days, not quarters.
We don't rank by blind and non-contextualized CVSS scores. We rank by what breaks the chain.
Two findings carry the same score. One sits on the only path between a standard workstation and your domain administrators. The other sits on a segment nobody can reach. A severity score cannot tell them apart. Attack-path analysis can.
Aegis models the routes through your environment the way an operator would: what is reachable, what is exploitable, what it yields, and what that yield unlocks next. Then it looks for the chokepoint, the single change that severs the largest number of those routes at once.
Effectiveness is weighted against reality, not theory. A fix that eliminates six paths but requires a domain-wide restart may be scheduled behind one that eliminates four and needs no downtime at all. You see the reasoning, the trade-off, and the expected reduction in exposure before you approve anything.
This is not a language model guessing. Attack chains and the ranked plan are produced by decision tree algorithms over collected configuration state. The same environment always yields the same chains and the same recommendation, and every branch is inspectable. Deterministic, repeatable, and auditable, because nobody should have to take a model's word for which change to make on a domain controller.
One console. Your whole estate. Plain language.
Everything Aegis collects lands in a single dashboard: estate-wide posture, open chains, machines running unsupported operating systems. Every figure drills to the hosts and evidence beneath it.
Acting on it does not require writing a script. State the change in plain language and Aegis turns it into a scoped plan for each affected machine. Guidance is sharpened by anonymised benchmarks from comparable environments, so a 200-seat operator and a 5,000-seat bank are not handed the same sequence.
The model only reads the chat box. A language model translates what you type into a change plan you then review. It does not decide what to fix, does not rank findings, and never executes anything. Every instruction produces a proposal, and every proposal requires sign-off.
One of us broke into these networks. The other builds the models.
Aegis comes out of years of penetration testing and red team work across financial services, energy, and maritime and shipping. The pattern was the same almost everywhere: compromise an estate through a chain of well understood, entirely fixable misconfigurations, write it up, hand it over, and come back the following year to find the same chain intact.
That is not negligence. It is capacity. The IT team knew exactly what the report said. They never had the time, the tooling, or the confidence to make the change safely on a live estate, so the findings aged in a spreadsheet while the paths stayed open. Watching engineers do that work by hand, one host at a time, is the reason this product exists.
The other half of the founding team is an AI engineer who has shipped systems on top of a range of models, and who drew the line we now hold to: a model is good at understanding what you asked for, and the wrong tool for deciding what to change in your domain. So the language model sits on the chat box, and decision trees do the reasoning.
Automated does not mean unsupervised.
Aegis makes changes to production Windows environments. We designed it on the assumption that you will trust it slowly, and that you should.
Approval before execution
No change runs without explicit authorisation. Read-only mode is available indefinitely.
Scoped and staged
Pilot group, then a ring, then the estate. Scope by OU, subnet, host group or tag.
Reversible by design
Prior state is recorded before every modification. Reverting a scope is a single action.
Fully auditable
Every proposal, approval and result logged with operator, timestamp and outcome.
What Aegis is not.
Aegis is not an EDR and does not replace one. It does not monitor process activity, inspect running memory, hunt for live intrusions, or respond to incidents in progress. It scans configuration state, works out what that state makes possible, and fixes it.
It is also not another generic vulnerability management scanner. It does not hand you thousands of unconfirmed findings to triage yourself. Findings are correlated into paths that actually exist in your environment, and the ones that matter are closed rather than listed.
We built the thing that closes the gap your existing tools leave open, not another one that tells you about it.
Aegis is still in development.
Subscribers get early insights and preferential pricing at launch.
One email when we launch. We won't spam or sell your e-mail address.
You're on the list.
We'll be in touch when early access opens, and not before.