Unprivileged by design零特权设计
One Node.js container on node:20-alpine. No root, no host namespace, no kernel module.一个 node:20-alpine 容器。无需 root,不共享宿主命名空间,不加载内核模块。
AegisTrust sec · Compliance automation AegisTrust sec · 合规自动化
An unprivileged container inside your own VPC scans cloud, IaC and AI runtime locally. Only a four-tuple verdict leaves, never your payload — and every result lands in an Ed25519 signed append-only ledger. 零特权容器部署在您自己的 VPC 内,在本地完成云配置、IaC 与 AI 运行态扫描。出网的只有四元组结论,绝不上传载荷;每条结果都写入 Ed25519 签名的追加式账本。
Platform平台底座
One Node.js container on node:20-alpine. No root, no host namespace, no kernel module.一个 node:20-alpine 容器。无需 root,不共享宿主命名空间,不加载内核模块。
Detection logic ships as zero-import WebAssembly, checked against SHA-256 and Ed25519 before every use.检测逻辑以零 import 的 WebAssembly 下发,每次使用前都校验 SHA-256 与 Ed25519。
The endpoint accepts exactly rule_id, status, detail and resource_hash. Anything else is dropped and logged.上报端点只接受 rule_id、status、detail、resource_hash,其余一律丢弃并留告警。
Entries are hash-chained and sealed with a KMS-held Ed25519 key, so a DBA cannot quietly rewrite history.条目哈希链式串联,并由 KMS 持有的 Ed25519 私钥签名——DBA 无法悄悄改写历史。
Capabilities能力清单
Status reflects the current build, not a roadmap. Everything listed is deployed. 状态以当前构建为准,不是路线图。下列能力均已上线。
Heartbeat, an application-layer HTTP forward proxy via HTTP_PROXY, and an offline NDJSON queue.心跳保活、通过 HTTP_PROXY 接入的应用层正向代理,以及离线可写的 NDJSON 队列。
Base, AI and Web3 modules hot-update from the control plane; unentitled ones never transfer a byte.核心、AI、Web3 三个模块支持控制面热更新;未订阅模块在传输任何字节前即被拒绝。
Blocks a tool call between the model deciding and the tool running — the only point a block can prevent the action.在「模型已决定」与「工具真的执行」之间拦截——只有这个位置能真正阻止动作。
Precise Markdown patches, read-only PR review comments and generated safety tests. Never merged for you.精确 Markdown 补丁、只读 PR 评论拦截与配套安全测试,绝不替您合并。
A read-only view with one-click verification of the signed chain and downloadable KMS-signed JSON.面向外部审计师的只读大盘,一键校验签名哈希链,并可下载 KMS 签名 JSON。
A block on one node contributes a one-way hash and a threat label. No plaintext leaves the tenant.某节点的一次拦截以单向哈希与威胁标签进入共享情报库,明文不出租户。
A third-party verifiable SVG badge served from a public endpoint, no account required.由公开端点直出的、第三方可独立验证的 SVG 徽章,无需账号。
Boundaries可信边界
Every claim a security buyer has to defend in review is listed here — including the ones that would have been easy to fake. 这里是安全买方要写进架构评审的每一条主张——也包括那些本最容易注水、但我们拒绝注水的部分。
Kernel capture sees only TLS ciphertext; making it see plaintext needs privilege or TLS termination. We take the application layer instead.内核态抓到的只有 TLS 密文;要看明文就得挂特权探针或改成 TLS 终结。我们因此选择应用层。
Ed25519 signatures over an append-only Merkle chain give an auditor the same practical guarantee — checkable with a public key.Ed25519 签名加追加式默克尔链,给到审计师同等实用的保证,而且拿一把公钥就能验。
Read and comment only. Patches are proposals a human applies; the decision stays with you.只读与评论。补丁是需要人工应用的提案,最终决定权始终在您那边。
Modules and plans are handled through a reviewed request in the console. There is no fake checkout page anywhere in this product.模块与订阅目前通过控制台内的人工申请完成。本产品中不存在任何假的收银台页面。
Generate a single-line unprivileged Docker command with a short-lived token, or run a read-only pre-flight scan first. Nothing is installed until you decide it should be. 生成一条带短效令牌的零特权 Docker 启动命令,或先跑一次只读预检扫描。在您决定之前,不会安装任何东西。