Aegis scans any codebase against 170+ security test types,
secrets, SAST, dependencies, IaC, cloud, containers, Kubernetes & CI/CD, with a built-in
engine that needs zero setup. One posture score, compliance mapping, exportable reports.
LIVE
3.3K active users this month59 countries
Static analysis: your code is never executed Live OSV.dev CVE intelligence OWASP · CIS · PCI-DSS · NIST SSDF
The platform
Ship fast without shipping vulnerabilities
Aegis is a developer-first application security platform. Connect a repository
and our native engine runs 119 checks instantly, no agents, no CI plumbing, no tool
zoo to maintain. Bring your own scanners as optional integrations when you want even deeper
coverage. Everything rolls up into a single posture score and an auditor-ready report.
0
setup steps
12+
languages & ecosystems
<60s
to first results
Posture overviewlive demo
62
Grade C · 18 open findings across 6 categories
Secrets
3
SAST
6
Dependencies
4
IaC
3
Containers
2
Capabilities
One platform, complete coverage
From the first commit to the production pipeline, Aegis covers the entire software supply chain.
Zero-setup native engine
119 built-in checks run in pure Python, no binaries to install, no CI to configure. Works the moment you sign in, on any language.
Dependencies are checked against the OSV.dev database in real time across PyPI, npm, Go, Maven, RubyGems, crates & more.
Compliance mapping
Every finding maps to OWASP Top 10, CIS Benchmarks, PCI-DSS v4 and NIST SSDF: turn raw results into audit evidence.
Fast, cancellable scans
Async scanning with live progress and a stop button. Pick exactly which categories and tools run per scan.
Reports & history
Export board-ready PDF and CSV reports. Logged-in teams get full scan history and trend tracking.
How it works
Secure code in three steps
1
Connect a repository
Sign in with GitHub and pick a repo, paste any public URL, or try the bundled sample. No agents or webhooks required.
2
Run a scan
Choose a profile or hand-pick categories. The Aegis engine and your selected integrations run in parallel with live progress.
3
Fix & prove it
Triage findings by severity, see your posture score and compliance status, and export a report for stakeholders.
Coverage
Everything you build, scanned
Pricing
Free for everyone, right now
Aegis is in early access: every feature below is unlocked for free, no credit card, ever, while that's true.
Free during early access
Everything, unlocked
$0
All 176 security test types, for individuals and teams.
All 119 built-in checks + 57 integrations
Public & private repository scans
Posture score & compliance view
Full scan history
PDF & CSV export
Guest & GitHub sign-in
Enterprise
Custom
For security & platform orgs with specific needs.
SSO / SAML & RBAC
Self-hosted / VPC deployment
Custom policy-as-code
API & CI/CD gating
Dedicated support & SLA
Our mission
Security that meets developers where they are
Aegis was founded on a simple belief: security shouldn't slow teams down or require a
specialist to operate. We package the world's best open security tooling, and our own zero-setup
engine, into one fast, beautiful platform any engineer can run in seconds.
We're built on open standards (SARIF, OSV, CycloneDX) and committed
to transparency. SOC 2 Type II is on our roadmap.
2026
Founded
Open
Standards-first
Dev-first
Built for engineers
Remote
Global team
FAQ
Frequently asked questions
Everything developers ask before their first scan.
What is a DevSecOps repository scanner?
A DevSecOps repository scanner analyses your source code and configuration
without executing it, looking for hardcoded secrets, insecure code
patterns (SAST), vulnerable dependencies (SCA), and misconfigured
infrastructure-as-code. Aegis runs 176 such test types and rolls the
results into one posture score.
Do I need to install any tools to use Aegis?
No. Aegis ships a native engine of 119 checks written in pure Python,
so scanning works the moment it boots, on any machine, for any language. The
57 external CLI scanners are optional integrations that deepen results,
not requirements.
Which compliance frameworks does Aegis map findings to?
Every finding maps to OWASP Top 10, CIS Benchmarks,
PCI-DSS v4 and NIST SSDF. Each framework shows per-control
pass/fail status alongside the number of open findings, so you can hand the
report straight to an auditor.
Is my source code safe when I run a scan?
Yes. Aegis performs static analysis only: your repository is cloned
into a temporary directory, inspected, then discarded. Your code is never
executed, and guest scans are never persisted.
Is Aegis free?
Yes. Aegis is free for everyone during early access: all 119
built-in checks, all 57 integrations, private repositories, scan
history and PDF/CSV export, at no cost and no credit card required.
Contact
Talk to us
Questions, a demo, or enterprise needs? We'd love to hear from you.
Emailhello@aegissec.dev
Salessales@aegissec.dev
Response timeWithin 1 business day
HQRemote-first · United Kingdom
Ready now?
Run your first scan in under a minute, no card required.
Start securing your code
Sign in to save history & export reports, or run a scan as a guest.
or
Your profile
Shown next to your scans and in scan history.
AegisAppSec Platform
Start a security scan
The Aegis engine runs 100+ built-in checks, no installs needed. Add integrations for extra depth.
1 · Source
Scans the bundled deliberately-insecure sample app, perfect for a quick demo.