Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
aegis-latent-core — Self-hosted evidence gateway for AI systems: fail-closed policy, WAF, egress controls, signed durable MMR proofs, and offline verification across LLM providers. | Kitploit
أدوات/GitHubGitHub/juanlunaia/aegis-latent-core
CryptographyCloud SecurityThreat IntelligenceAPI SecurityAI SecurityLog Analysis
GitHubjuanlunaia/aegis-latent-core

aegis-latent-core

Self-hosted evidence gateway for AI systems: fail-closed policy, WAF, egress controls, signed durable MMR proofs, and offline verification across LLM providers.

عرض المستودع
184107منذ 5 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
الموقع الإلكتروني
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Aegis Latent Core

The evidence gateway for AI systems that must be explainable after the fact.

Aegis sits between your application and one or more LLM providers. It admits, bounds, redacts, forwards and records governed calls, then emits portable cryptographic evidence that an independent verifier can check offline. The core promise is deliberately narrow: a response is not released until the governed evidence path has reached its declared commit point. That turns “we think the logs are intact” into a reproducible verification workflow.

Built for: AI platform teams, security engineers, regulated operators, incident responders and auditors who need a self-hosted control plane for provider calls — not another model, hosted observability dashboard or compliance badge.

What makes it different: fail-closed admission, append-only Merkle Mountain Range evidence, signed records, offline Python/TypeScript proof verification, bounded streaming semantics, and explicit claim boundaries. What it is not: a model, a universal WAF, a certification, a guarantee that model output is true, or a substitute for your identity, retention, privacy or regulatory program.

release CI Security coverage License

Every load-bearing claim in this file carries a locator and a stated boundary; the gates that enforce that discipline run in CI.

Start here: prove an evidence record yourself · choose a deployment profile · read the threat model · inspect the claims matrix

Current release: v5.0.2 — the published Apache-2.0 release, published 2026-10-01. GitHub Release, PyPI aegis-latent-core, PyPI aegis-latent-sdk and npm aegis-latent-sdk were read back at 5.0.2; GHCR was not independently readable from this environment (Release Status §1.0d). The GitHub Release carries 31 assets, including SHA256SUMS; the registry package versions read back are 5.0.2. The previous release 5.0.1 and its stronger signature/provenance readbacks remain documented in §1.0a–§1.0b. No current GHCR verification claim is made here. The previous release, v5.0.0, was published 2026-09-16 on the same surfaces (§1.0). There is no 4.2.0; the number was skipped.

First published version with the gateway on PyPI: v4.1.2, read back on 2026-09-04 — signed annotated tag, GitHub Release with 31 assets, PyPI aegis-latent-core 4.1.2, PyPI aegis-latent-sdk 4.1.2, npm aegis-latent-sdk 4.1.2, and GHCR gateway and dashboard images. 4.1.2 is the first version installable from PyPI as aegis-latent-core; before it the gateway came from source or GHCR only. The npm version list skips 4.1.1, whose publish step failed. A v4.1.0 release object also exists but was created outside the pipeline and carries no assets; ignore it. The two 4.1.2 PyPI gateway artifacts are byte-different from the release assets of the same name — same content, different build host — so SHA256SUMS does not cover those downloads; the 5.0.1 PyPI gateway artifacts match it. See Release Status for provenance and readback.


The problem

Your AI decisions are logged to a database your administrators can edit. When someone asks what the model was told six months ago, you answer from records the interested party could have changed.

In a regulated industry that is not a paperwork problem — it is an existential one. The regulator, the court and the auditor each ask the same question, and "our logs are probably fine" is not an answer they accept:

  1. A record the interested party could have altered is not evidence — it only reads as evidence until someone with a reason to doubt it asks one question.
  2. You already owe someone a record you can stand behind — EU AI Act Art. 12, HIPAA audit controls, SEC 17a-4's audit-trail alternative, MiFID II. Those are your obligations; this software is an input to them, never a discharge of them.
  3. The fix has to be checkable by someone who distrusts you, or it is the same problem wearing better clothes.

The Aegis solution

  • Append-only, tamper-evident MMR. Every record is a leaf in a Merkle Mountain Range. A portable inclusion proof (O(log n), no zero-knowledge claim) lets a third party verify a disclosed record against a root they obtained independently. verify_integrity() detects tampering on read; tampering is detected, not prevented — see the boundaries below.
  • Cryptographic sealing. Each record is hashed into a chain link and signed — HMAC by default, Ed25519 (RFC 8032) or ML-DSA-65 (FIPS 204) where configured, with an HSM path in the enterprise server. Optional per-subject shredding (AES-256-GCM key destruction) erases plaintext from a ciphertext holder's view without changing the MMR root or previously issued proofs.
  • Zero-trust verification. Proofs verify offline: a 313-line pure-Python verifier, a TypeScript twin with the same semantics, and zero network calls. No trust in the gateway, the vendor, or the operator who discloses the record — only in a root you obtained through a channel the discloser does not control.
  • Regulatory inputs. MiFID II Art. 16(6)/16(7) and MiFIR Art. 25(1) record-keeping framing (durable, ordered-within-process records; no orders — RTS 24 — and no clock traceability — RTS 25); EU AI Act Art. 12 logging inputs (commit-before-response, tamper detection, verifiable inclusion); HIPAA Safe-Harbor-style pattern redaction; ISO/IEC 27037-style extracts. These are technical inputs, not compliance. No certification exists, none is in progress, and whether any obligation is met is a determination for you and your assessor (CLM-039 is LEGAL-REVIEW-REQUIRED).

→ Prove it yourself — twelve lines of Python, no call to our servers, three cases of which two must fail.

pip install aegis-latent-sdk aegis-latent-core   # verifier + gateway, both 5.0.1 on PyPI
python tools/sales/prove_it/prove_it.py --demo   # accepts one record, rejects two forgeries
python -m examples.demo                          # gateway + mock upstream, tamper detected

Both commands run from a checkout of this repository; what each one shows and does not show.


Architecture at a glance

تنزيل الأداة