The compliance analysis engine that runs inside your perimeter.
Aegis assesses your security policies against NIST CSF 2.0, ISO/IEC 27001:2022, SOC 2, and GDPR: quantitative scores, clause-level gaps, and audit-ready remediation, delivered by a sealed package that keeps your documents on your own infrastructure.

Gap assessments are stuck between two bad options.
The manual way is slow and consultant-bound.
A framework gap assessment means weeks of a consultant reading policies line by line against hundreds of controls. It is expensive, it goes stale the moment a policy changes, and the working notes rarely survive to the next audit cycle.
The chatbot way is fast and unaccountable.
Pasting policies into a general-purpose AI chat gives you answers nobody can verify: coverage is incomplete, the score changes every time you ask, and your most sensitive documents just left your perimeter. No auditor accepts "the chatbot said so".
An engine, not an AI chat.
A chat wrapper sends your document to a model and formats the reply. Aegis is a deterministic pipeline in which the model is one bounded, replaceable component: the catalogs, the scoring, the merge rules, and the audit trail are all engine code, not prompts.
From upload to audit-ready in five steps.
- 1
Upload
Bring your policy documents plus any supporting evidence. DOCX and PDF, up to ten documents per run.
- 2
Analyze
One pass per framework over every control. Automatic framework detection or pick your own set.
- 3
Review gaps
Clause-level findings with per-function breakdowns, crosswalk hints, and two honest numbers: effective and policy-only.
- 4
Remediate
Aegis proposes a change set. You accept, edit, or reject each change in a word-level diff review.
- 5
Export
PDF, DOCX, XLSX, and CSV, including scope, coverage provenance, dispositions, and the decision log.
Four frameworks, one consistent engine.
Every framework normalizes to the same structure, so a run can assess one document set against all four at once. 214 curated crosswalk mappings connect related controls across frameworks, and they are deliberately report-only: a mapping never changes a score.
ISO/IEC 27001:2022
93 Annex A controls across 4 themes
SOC 2
61 criteria across all five Trust Services Categories
GDPR
36 obligations across 4 areas
NIST CSF 2.0
106 subcategories, verbatim official text
Your documents stay home.
Aegis ships as a sealed Docker package on your infrastructure. The only network egress is the model API, and even that is governed, logged, and visible.
Default-deny egress
One allow-listed host. Every attempt, allowed or denied, lands in a visible egress ledger.
Signed content updates
Framework updates are Ed25519-signed, downgrade-proof, atomically installed, and one-click reversible.
Immutable audit trail
Versions are immutable, runs pin what they assessed, and raw verdicts are never rewritten.
Enterprise access control
Five app roles, invite-only onboarding, TOTP MFA with org-wide enforcement.
Human-gated remediation
The AI proposes. Every applied change carries a named human decision.
Nothing extra in the box
No embedding or vector libraries ship in the image. Smaller surface, honest scope.
- 4
- Frameworks
- 296
- Controls enumerated
- 214
- Crosswalk mappings
- 29
- Table data model
- 266
- Automated tests
- 2
- Architectures
Built for the people who own the audit.
Internal compliance teams
Continuous readiness between audits. Track effective scores per project, resolve gaps with evidence, and keep a record an auditor can reconstruct.
Advisory firms and vCISOs
Per-client projects, reusable certification scope profiles, and multi-framework runs map directly to how engagements actually work.
Audit preparation
Evidence with provenance, dispositions with mandatory justification, and exports that show who decided what, and when.
See your own policy scored in 30 minutes.
A live walkthrough on your sample policy, offline, with your questions answered by the people who built it.