
Self-hosted evidence gateway for AI systems: fail-closed policy, WAF, egress controls, signed durable MMR proofs, and offline verification across LLM providers.
The evidence gateway for AI systems that must be explainable after the fact.
Aegis sits between your application and one or more LLM providers. It admits, bounds, redacts, forwards and records governed calls, then emits portable cryptographic evidence that an independent verifier can check offline. The core promise is deliberately narrow: a response is not released until the governed evidence path has reached its declared commit point. That turns “we think the logs are intact” into a reproducible verification workflow.
Built for: AI platform teams, security engineers, regulated operators, incident responders and auditors who need a self-hosted control plane for provider calls — not another model, hosted observability dashboard or compliance badge.
What makes it different: fail-closed admission, append-only Merkle Mountain Range evidence, signed records, offline Python/TypeScript proof verification, bounded streaming semantics, and explicit claim boundaries. What it is not: a model, a universal WAF, a certification, a guarantee that model output is true, or a substitute for your identity, retention, privacy or regulatory program.
Every load-bearing claim in this file carries a locator and a stated boundary; the gates that enforce that discipline run in CI.
Start here: prove an evidence record yourself · choose a deployment profile · read the threat model · inspect the claims matrix
Current release:
v5.0.2— the published Apache-2.0 release, published 2026-10-01. GitHub Release, PyPIaegis-latent-core, PyPIaegis-latent-sdkand npmaegis-latent-sdkwere read back at5.0.2; GHCR was not independently readable from this environment (Release Status §1.0d). The GitHub Release carries 31 assets, includingSHA256SUMS; the registry package versions read back are5.0.2. The previous release5.0.1and its stronger signature/provenance readbacks remain documented in §1.0a–§1.0b. No current GHCR verification claim is made here. The previous release,v5.0.0, was published 2026-09-16 on the same surfaces (§1.0). There is no4.2.0; the number was skipped.First published version with the gateway on PyPI:
v4.1.2, read back on 2026-09-04 — signed annotated tag, GitHub Release with 31 assets, PyPIaegis-latent-core4.1.2, PyPIaegis-latent-sdk4.1.2, npmaegis-latent-sdk4.1.2, and GHCR gateway and dashboard images.4.1.2is the first version installable from PyPI asaegis-latent-core; before it the gateway came from source or GHCR only. The npm version list skips4.1.1, whose publish step failed. Av4.1.0release object also exists but was created outside the pipeline and carries no assets; ignore it. The two4.1.2PyPI gateway artifacts are byte-different from the release assets of the same name — same content, different build host — soSHA256SUMSdoes not cover those downloads; the5.0.1PyPI gateway artifacts match it. See Release Status for provenance and readback.
Your AI decisions are logged to a database your administrators can edit. When someone asks what the model was told six months ago, you answer from records the interested party could have changed.
In a regulated industry that is not a paperwork problem — it is an existential one. The regulator, the court and the auditor each ask the same question, and "our logs are probably fine" is not an answer they accept:
verify_integrity() detects tampering on read; tampering is detected, not prevented — see the boundaries below.CLM-039 is LEGAL-REVIEW-REQUIRED).→ Prove it yourself — twelve lines of Python, no call to our servers, three cases of which two must fail.
pip install aegis-latent-sdk aegis-latent-core # verifier + gateway, both 5.0.1 on PyPI python tools/sales/prove_it/prove_it.py --demo # accepts one record, rejects two forgeries python -m examples.demo # gateway + mock upstream, tamper detectedBoth commands run from a checkout of this repository; what each one shows and does not show.