Aegis.

The compliance analysis engine that runs inside your perimeter.

Aegis assesses your security policies against NIST CSF 2.0, ISO/IEC 27001:2022, SOC 2, and GDPR: quantitative scores, clause-level gaps, and audit-ready remediation, delivered by a sealed package that keeps your documents on your own infrastructure.

Runs offline296 controls enumeratedAudit-ready by design
aegis.internal
Aegis dashboard with the organization compliance score, scored project cards, and recent runs
The problem

Gap assessments are stuck between two bad options.

The manual way is slow and consultant-bound.

A framework gap assessment means weeks of a consultant reading policies line by line against hundreds of controls. It is expensive, it goes stale the moment a policy changes, and the working notes rarely survive to the next audit cycle.

The chatbot way is fast and unaccountable.

Pasting policies into a general-purpose AI chat gives you answers nobody can verify: coverage is incomplete, the score changes every time you ask, and your most sensitive documents just left your perimeter. No auditor accepts "the chatbot said so".

Why Aegis is different

An engine, not an AI chat.

A chat wrapper sends your document to a model and formats the reply. Aegis is a deterministic pipeline in which the model is one bounded, replaceable component: the catalogs, the scoring, the merge rules, and the audit trail are all engine code, not prompts.

Every control, every time. The framework catalogs are enumerated structured data, not a retrieval index. All 296 controls are assessed on every run, so gaps can never be silently dropped.
Deterministic scoring. Fixed weights, a reproducible merge across document chunks, and no cross-framework averaging. The engine computes the numbers; the model never invents them.
An engineered LLM boundary. Structured output through forced tool use, computed token budgets, and an explicit retry ladder with model fallback. A failed framework degrades a run to partial instead of poisoning it.
The engine grades the AI. Policies drafted by the built-in generator are validated by the same analyzer that grades everything else, then revised in a loop until they clear the bar.
The workflow

From upload to audit-ready in five steps.

  1. 1

    Upload

    Bring your policy documents plus any supporting evidence. DOCX and PDF, up to ten documents per run.

  2. 2

    Analyze

    One pass per framework over every control. Automatic framework detection or pick your own set.

  3. 3

    Review gaps

    Clause-level findings with per-function breakdowns, crosswalk hints, and two honest numbers: effective and policy-only.

  4. 4

    Remediate

    Aegis proposes a change set. You accept, edit, or reject each change in a word-level diff review.

  5. 5

    Export

    PDF, DOCX, XLSX, and CSV, including scope, coverage provenance, dispositions, and the decision log.

Frameworks

Four frameworks, one consistent engine.

Every framework normalizes to the same structure, so a run can assess one document set against all four at once. 214 curated crosswalk mappings connect related controls across frameworks, and they are deliberately report-only: a mapping never changes a score.

ISO/IEC 27001:2022

93 Annex A controls across 4 themes

SOC 2

61 criteria across all five Trust Services Categories

GDPR

36 obligations across 4 areas

NIST CSF 2.0

106 subcategories, verbatim official text

Security & trust

Your documents stay home.

Aegis ships as a sealed Docker package on your infrastructure. The only network egress is the model API, and even that is governed, logged, and visible.

Default-deny egress

One allow-listed host. Every attempt, allowed or denied, lands in a visible egress ledger.

Signed content updates

Framework updates are Ed25519-signed, downgrade-proof, atomically installed, and one-click reversible.

Immutable audit trail

Versions are immutable, runs pin what they assessed, and raw verdicts are never rewritten.

Enterprise access control

Five app roles, invite-only onboarding, TOTP MFA with org-wide enforcement.

Human-gated remediation

The AI proposes. Every applied change carries a named human decision.

Nothing extra in the box

No embedding or vector libraries ship in the image. Smaller surface, honest scope.

4
Frameworks
296
Controls enumerated
214
Crosswalk mappings
29
Table data model
266
Automated tests
2
Architectures
Who it's for

Built for the people who own the audit.

Internal compliance teams

Continuous readiness between audits. Track effective scores per project, resolve gaps with evidence, and keep a record an auditor can reconstruct.

Advisory firms and vCISOs

Per-client projects, reusable certification scope profiles, and multi-framework runs map directly to how engagements actually work.

Audit preparation

Evidence with provenance, dispositions with mandatory justification, and exports that show who decided what, and when.

See your own policy scored in 30 minutes.

A live walkthrough on your sample policy, offline, with your questions answered by the people who built it.