Aegis Red

Authorized assurance for AI applications and agents. Authorized tests. Pass or Fail. No exploit cookbook.

Architecture

How a seed becomes Pass or Fail

Select a component to see what talks to what. The harness sits in the middle. The catalog is YAML. Evidence is hashed files — not a company database.

Hold

The LLM is not the judge. Optional extractor mode llm fills reply_claims_v1 at temperature 0. Python oracles plus twin state decide hold or breach. Unclear extract is inconclusive, not Pass.

Catalog Harness System under test Extract (not judge) Judge — oracles

1 · Surfaces

2 · Catalog

3 · Envelope

4 · System under test

5 · Extract — not judge

6 · Judge and proof

One seed

Ordered interaction on a single run.

  1. Load seed, persona, fixtures from the catalog
  2. Governor issues a token or skips
  3. RedActor speaks the intent
  4. Adapter calls one SUT; twin snapshot captured
  5. Extractor fills claims (local or LLM) — no Pass/Fail
  6. Oracles score effects; outcome written
  7. Lake hashes the bundle onto the previous hash