Security products promise. AegiFlow proves.
AegiFlow exists because most web protection is sold as a green checkmark you are asked to trust. We build the opposite: an operations layer where every state — protected, observed, recovered — carries recent, inspectable evidence.
The principles we operate by
These principles define release gates and data rules; the capability registry shows which ones have current evidence.
Unknown is never green. A check that has not run recently is shown as Unknown. We would rather show you an honest gap than a comfortable lie.
Every action has a way back. The broker requires bounded scope, a time limit and a rollback path; provider changes count only after receipt-backed verification.
The visitor is never the test subject. Analysis runs in parallel, out of the request path. Traffic changes only after explicit verification gates pass.
Availability is exercised, not assumed. Signed bundles and drill receipts prove only the tested scope; independent activation, login, checkout and production-apex recovery remain separate gates.
How the platform came to be
A condensed, honest timeline — the same one recorded in our release history.
- 2026-07-23
The public website moves to a single bilingual source with immutable, checksummed releases.
- 2026-07-27
Self-hosted identity goes live: OIDC sessions, passkeys, TOTP and step-up verification.
- 2026-07-29
Edge telemetry v5: minute-level rollups and live traffic windows power the dashboard.
- 2026-07-30
The first production service routes its public traffic through the AegiFlow edge, with blocking turned off.
- 2026-07-31
The public Advisory Database launches and grows automatically every day.
AegiFlow is operated as a bounded validation environment while required safety checks remain open. We publish what works, what runs without blocking, and what is not done yet — on every page.
See the evidence for yourself.
Add a domain without changing its traffic, or read how every capability is verified.