Aegis Red

Authorized assurance for AI applications and agents. Authorized tests. Pass or Fail. No exploit cookbook.

Authorized harness

Prove the agent was not allowed to change the world.

Authorized assurance for AI applications and agents. Authorized tests. Pass or Fail. No exploit cookbook. Aegis Red scores effects — undeclared tools stayed denied, secrets did not leak, a fake policy did not bind — with hashed workpapers.

Nudge catalogSafety, security, banking, insurance
Pass / FailOracles on twin or live agent
EvidenceChain-hashed bundles and lineage

What it is

An authorized assurance harness for AI applications and agents.

You describe intents (seeds) and oracles. The harness talks to a system under test, records the transcript, and scores Pass or Fail. Production stays shadow-only unless you write otherwise.

Hold

Effects, not wording

Pass means the control held on the system.

Hold

Intents, not recipes

Seeds are fixtures and oracles. Bypass payloads do not ship.

Hold

Twin, then live

In-process twin first. Same seeds hit HTTP or a model API.

Hold

Workpapers, not a badge

Hashed bundles: utterance, reply, tools, lineage, go / no-go.

Coverage

Industries, families, and auditor folders.

The free wheel is a nudge across every industry pack. Complete coverage fills the remainder. Runtime subset of NIST AI RMF, ISO 42001, OWASP LLM, OSI OSAID 1.0, and the EU AI Act — agent behavior under fixtures, not a full management-system certificate.

Free nudge

Safety (Tech / AI): content safety, injection, instruction integrity, hallucination, privacy, tools, summarization, memory, swarm, lineage, change control, plus OWASP LLM, OSI OSAID 1.0, NIST AI 600-1 GAI, ISO/IEC 42001 Annex A, and EU AI Act auditor bodies.

Security: injection, instruction, privacy, tool contract, tool access, policy robustness, lineage.

Banking journeys (named rows), insurance skeleton, community seed store. Harness, portal, twin, live HTTP demo.

Complete coverage

The rest of the industry corpus (~300 banking rows plus control functions), auditor folders (OSS, NIST, ISO, OWASP, AI Act) under each industry, repeat campaigns, and the live-hook expectation for tools and state.

Request it with org, contact, industry, and the problem you are trying to solve. We do not publish that remainder in the free wheel.

How it is different

Others score prompts. We exam whether the agent was allowed to act.

No product names. The distinction is the job, not the logo.

JobTypical elsewhereAegis Red
What is scoredWording, attack strings, or a questionnaireEffects on tools, state, and policy bind
What shipsPayload lists or a slide crosswalkIntent + fixtures + oracles; hashed bundles
Where it runsChat-only or a mock that is not the agentTwin, then live adapter returning tools and state
Mesh / swarmSingle-turn chatPrivilege union and silent handoff are first-class
Policy rewrite claimOften out of scope or a recipeIntercept: claimed policy, tools that must stay denied
EvidenceA score and a screenshotLineage (model / prompt / actor / tool) and go / no-go
What we will not claim—We do not find every vulnerability. We do not issue the certificate.

Who benefits

Role by role, what this product is for.

CISO / CRO

Go / no-go on whether AI directives held. Board line with hashed proof. Complete coverage maps to the internal risk register — not a slide.

Engineer

Install the signed wheel, run the twin, then point the same seeds at a live agent. Adapter work is time, not a payload library.

UAT / QA

Portal in plain language. Add a test, run it, download Pass/Fail CSV. No YAML required for the first two seeds.

Founder / individual

Free install after a short form. Prove the method on safety and a vertical nudge before you buy depth.

Legal, compliance, risk, audit

Domain families and examiner-sample bundles when complete coverage is enabled. Runtime subset — not vendor DD or training-data audits.

Examiner / audit partner

You sample workpapers. You do not buy the product. Lineage is on the material act.

Start now

Install the signed free wheel.

Tell us whether you are an organization, a startup, or an individual. We give you pip install aegis-red from PyPI (signed wheel, currently 0.2.3). Site: aeigisred.ai. GitHub source stays private. Authorized tests. Pass or Fail. No exploit cookbook.

By installing you agree this is a free evaluation copy, intents-only, and not an attack toolkit.

Complete coverage

Request the commercial pack.

We need the organization, who to contact, the industry you are trying to solve, and the use case. That is how the remainder is scoped — not a public download.