Aegis Cyber Intelligence · Under development
Security tools detect events.
Aegis detects trajectory.
A privacy-preserving cyber precursor intelligence platform designed to identify when users, devices, cloud identities and business workflows begin moving toward breach, ransomware, fraud, insider abuse or AI-enabled attack—before the incident fully materialises.

Not another SIEM, XDR or UEBA
Built for the stage before
the critical alert.
Conventional security platforms are essential, but most are optimised to identify suspicious or malicious events once enough evidence already exists. Aegis is designed to sit above and beside those controls, correlating smaller changes across systems into an earlier view of emerging threat trajectory.
Event detection
SIEM, XDR and UEBA platforms typically identify rules, anomalies, indicators or suspicious activity within their own telemetry domain.
Precursor convergence
Aegis asks whether individually weak signals across identity, endpoint, cloud, SaaS, network and financial behaviour are beginning to form a credible threat pattern.
Threat progression
The system tracks how risk is changing, which entities are connected, what the likely next attacker action may be and which containment step is justified now.
The intelligence layer
From isolated alerts
to an evolving threat case.
Aegis is intended to convert fragmented telemetry into a living, explainable risk graph connecting users, devices, workloads, cloud roles, SaaS identities, external infrastructure and business workflows.
Detect acceleration
Measure not only whether risk is high, but whether it is rising abnormally fast across related entities.
Forecast the next move
Map observed precursor chains to likely credential expansion, persistence, staging, exfiltration, fraud or destructive action.
Explain every score
Expose the contributing signals, confidence, blast radius, business criticality and recommended action behind each case.
Complement existing controls
Deliver risk scores and threat cases into current SIEM, SOAR, XDR, Slack, webhook and analyst workflows rather than forcing replacement.
Aegis Veil · Adaptive containment and deception
Protect the real environment.
Divert the intrusion.
When evidence, customer policy and risk level support it, Aegis Veil is designed to remove a suspicious identity, session, device or workload from authentic systems and route it into an isolated, instrumented environment. Real client data stays protected while the intrusion is presented with believable synthetic services and information.
Cut off authentic access
Use approved customer controls to reduce privilege, revoke sessions, restrict egress, block sensitive operations and isolate affected workloads.
Present synthetic targets
Route suspicious activity toward decoy repositories, documents, APIs, identities or services containing no real client data, credentials or reusable secrets.
Capture the attack path
Record requested resources, commands, payload hashes, timing, observed IP addresses, domains and progression into the immutable Aegis evidence chain.
Safety overrides engagement
Ransomware, active exfiltration, destructive activity or integrity failure triggers immediate isolation and termination rather than extended observation.
Veil is designed to make diversion difficult to recognise, but no responsible system can guarantee that a capable intruder will never detect containment. Decoys have no route back to production, contain no authentic client data, and remain subject to customer approval, audit, rollback and an emergency kill switch.
Initial product focus
Identity, SaaS and cloud
precursors first.
The first production path is deliberately narrow: identity-driven breach and ransomware precursors across Microsoft 365 or Entra ID, Okta, AWS and Google Workspace, with endpoint, fraud, insider-risk and AI-threat modules added later.
Account takeover drift
MFA fatigue, rare ASN access, dormant-account reuse, privilege changes and unusual service-account behaviour.
Data and persistence signals
Suspicious OAuth grants, forwarding rules, mass downloads, exports and administrative changes.
Control-plane movement
Role assumptions, IAM expansion, new access keys, audit tampering and abnormal data-transfer paths.
Emerging attack surfaces
Prompt injection, AI-system misuse, sensitive-data leakage, synthetic phishing and malicious automation patterns.
Privacy and deployment
The client sees the threats.
Pythology sees system health.
Aegis is being built so that privacy is enforced by architecture. Customer telemetry, identities, content and threat cases remain isolated from Pythology's operational monitoring.
Aegis Managed
A dedicated encrypted tenant, private API connection and customer-side collector. The collector minimises and pseudonymises telemetry before transmission. Aegis services process only the signals the customer has approved; Pythology personnel do not routinely view customer cases or content.
Aegis Private
Processing, threat graphs, evidence and dashboards remain inside the customer's cloud account, VPC or on-premises environment. The customer controls encryption keys and access. Pythology receives only an outbound health heartbeat and cannot access the security data plane.
Operational health only
Collector availability, software version, queue depth, processing latency, CPU and memory health, certificate expiry, integrity checks and backup status.
Customer security activity
User identities, email or file content, internal logs, IP evidence, threat cases, alerts, employee activity, dashboard content or incident reports in Aegis Private deployments.
The Watchtower verifies that collectors, scoring services and dashboards are healthy without receiving the client's security evidence.
Protection scope
Outside exposure and
inside behaviour.
External monitoring does not require access to internal content. Internal precursor detection is enabled only through customer-authorised connectors and policies.
Attack-surface monitoring
Track DNS and certificate changes, unexpected public services, lookalike domains, exposed applications and changes to the organisation's internet-visible footprint.
Insider-risk precursors
Detect unusual access to restricted information, mass downloads, role misuse, abnormal repository cloning, file staging and other policy-defined deviations.
Outbound data-risk signals
Receive customer-controlled DLP and mail-security events such as sensitive-data matches, unusual external recipients, forwarding rules and blocked or overridden actions—without sending email bodies to Pythology.
Threat tags and reports
Link observed IPs, domains, hashes, accounts, devices and techniques into cases. Generate client-controlled evidence packages for insurers, legal teams or authorities while preserving uncertainty and chain of custody.
Enterprise and pilot enquiries
Aegis Cyber Intelligence begins
with a technical conversation.
Deployments require discovery across security architecture, available telemetry, data residency, integration scope, governance and the threat outcomes the organisation needs to improve.
Initial contact is used only to establish fit and arrange an appropriate technical discussion. Secure information exchange can be established later where required.
.jpeg)