Aegis Red

Authorized assurance for AI applications and agents. Authorized tests. Pass or Fail. No exploit cookbook.

Documentation

Install the signed wheel. Request complete coverage when you need the remainder.

Authorized assurance for AI applications and agents. Authorized tests. Pass or Fail. No exploit cookbook. GitHub source stays private. The free artifact is the Sigstore-signed wheel on PyPI (aegis-red 0.2.3). Public site: aeigisred.ai.

1. Install the signed wheel

Python 3.11+. Source is not a public clone. Install from PyPI, or use Start now if you want us to capture a short lead first:

python3 -m venv .venv
source .venv/bin/activate          # Windows: .venv\Scripts\Activate.ps1
python -m pip install -U pip
pip install aegis-red
aegis-red doctor
aegis-red try

aegis-red try opens http://127.0.0.1:8080 and a demo agent on port 8090. Tester UI: /app.

Air-gap / repo access: install the .whl from the GitHub Release (private) after checking SHA256SUMS. Do not unzip a source tree from the website.

2. Verify the signature

Release wheels are signed with Sigstore (GitHub Actions identity) and attested. After you have the .whl file:

python -m pip install sigstore
python -m sigstore verify github --repository aegis-red/aegis-red path/to/aegis_red-*.whl

Each PyPI upload attaches PEP 740 attestations via Trusted Publishing. GitHub source remains private.

3. Run a campaign

aegis-red run core_safety --sut twin
aegis-red run security_nudge --sut twin
aegis-red run starter_pack --sut twin

go exits 0. no-go (critical breach) exits 2. Evidence writes under data/evidence/ in the current directory (gitignored in source checkouts).

4. Tester portal

  1. Open /app.
  2. Try now → add a test in plain language → Run this test.
  3. Download Pass/Fail CSV.
  4. Pick one SUT: in-process twin, live HTTP, or a model API profile. One active at a time (AEGIS_SUT or the portal control).

5. What a seed is

The nudge catalog ships inside the wheel. YAML under catalog/domains/<industry>/seeds/: persona, utterance (intent), fixtures, success and failure oracles. Auditor evidence belongs under seeds/auditors/{oss,nist,iso,owasp,ai_act}/. User seeds you add in the portal write under the current directory, not into site-packages.

6. Connect your agent

Implement handle(seed, persona, utterance) -> Turn and register aegis_red.sut. The live HTTP demo expects tools and state, not chat-only Pass/Fail. Licensed source work is in CONTRIBUTING.md.

7. Free vs complete

The wheel does not include catalog/commercial/seeds. After you receive complete coverage, place seeds under ./catalog/commercial/seeds/ (current directory) and uncomment the commercial pack in a local aegis.yaml. aegis-red doctor reports nudge-only until that pack is enabled.

8. Request complete coverage

Use the public form: organization, contact, industry, use case. We scope the remainder from that — we do not email a generic cookbook.

Request complete coverage Install commands