AEGIS

AI-native Defensive Security Operating System · v1.0
Repository v1.0 · FROZEN Architecture COMPLETE Implementation AUTHORIZED AI Engine: gated on kernel

Overview

AEGIS materializes the frozen architecture defined in docs/architecture/ — 60 documents (~102,000 words) authorizing implementation of a defensive-only security platform whose objective is sustainable trust, not feature count.

Every implementation must comply with the Engineering Constitution (CLAUDE.md). No implementation may contradict an approved ADR, bypass the Security Kernel / Capability Broker / Policy Engine / Evidence Chain / Audit Chain, or skip Verification.

Quick Links

📚 Documentation public

/architecture/ · 60 docs

🎛 Dashboard CF Access

control.aishain.tech

🔌 API local-only

offline-first · no external endpoint

💚 Status up

/_edge/health

🔖 Version v1.0

FROZEN 2026-07-10

🐙 GitHub local

no remote · ARCH-mandated offline

🔗 XAI Integration edge shared

§ topology below

📖 Repository Spec

REPOSITORY-v1.0.md

📜 Constitution

CLAUDE.md

📗 Runbooks

/runbooks/

📋 ADRs

/adr/

🧪 Verification

/verification/

Implementation Priority (ARCH-60 §2 R-9)

  1. Security Kernel — Deterministic foundation
  2. Identity Engine
  3. Capability Broker (Kernel sub-module)
  4. Policy Engine
  5. Evidence Engine
  6. Audit Engine
  7. Runtime Risk Engine
  8. Verification Infrastructure
  9. Recovery Domain
  10. AI Safety Layer
  11. AI Engine — implemented only after the deterministic security foundation exists

XAI 連携トポロジー

Edge host
shared VPS · edge-caddy コンテナが aegis / xai / xcloud / gourmie の 5 vhost を集約
Docker network
edge · aegis-static は共通ネットワーク配下 (nginx:1.27-alpine)
TLS
Let's Encrypt · edge-caddy が自動更新
Cloudflare zone
xiora-official.com · DNS-only (proxy off)
Access control
public read-only · write methods → 405 に切替可能
WireGuard peer
non-peer · AEGIS は offline-first 設計 (意図的に非接続)
Provider tokens
none · 外部 SaaS 依存ゼロ
Version alignment
AEGIS v1.0 / XAI Dashboard P1-P6+Ops complete
Monitoring
XAI ControlCenter Dashboard が 監視のみ (統合ではなく観測)