Aegis documentation

What each part of Aegis does, what it needs from you, and what it will not tell you.

54 available23 need setup0 not built

Generated from the same registry the application reads, which is checked against the repository by a test. A capability that lost its implementation would fail that test rather than quietly keep its page here.

Identity and access

Who can see and change what, across single sign-on, roles and tenancy.

Source control

Reading repositories, and writing back to them as pull requests and checks.

Code and dependencies

What is wrong in the code and its dependencies, and how far it is actually reachable.

Supply chain

What you are installing and where it came from, before an advisory exists to warn you.

Cloud

Configuration, identity and data exposure across cloud accounts.

Runtime

What is happening in production, as opposed to what is in the repository.

Attack surface

What is reachable from the internet, including what nobody meant to publish.

Endpoints

Devices and virtual machines, and what is installed on them.

Governance and compliance

Turning findings into the evidence an auditor asks for, and recording the controls no scanner can see.

Platform

The parts that make the rest usable: limits, jobs, delivery and setup.