aegisgate-platform
Health Uyari
- License รขโฌโ License: Apache-2.0
- Description รขโฌโ Repository has a description
- Active repo รขโฌโ Last push 0 days ago
- Low visibility รขโฌโ Only 5 GitHub stars
Code Gecti
- Code scan รขโฌโ Scanned 12 files during light audit, no dangerous patterns found
Permissions Gecti
- Permissions รขโฌโ No dangerous permissions requested
Bu listing icin henuz AI raporu yok.
๐ก๏ธ Secure every AI interaction โ HTTP, MCP, A2A, LLM responses. Six pillars, one gateway, zero compromises. Self-hosted, fail-closed, enterprise-grade. 24K+ RPS, 87.4% coverage, 0 CVEs, red-team hardened. HA clustering, 153 detection patterns, 15+ compliance frameworks.
๐ก๏ธ AegisGate Security Platform
Secure every AI interaction. Six pillars. One gateway. Zero external dependencies.
๐ Website ยท ๐ Live Demo ยท ๐ Pricing ยท ๐ Docs ยท ๐ Security ยท ๐ฌ Discussions
๐งฉ Using AI without enterprise protections? AegisGate Lens is our free browser extension that brings 153 detection patterns to everyday AI conversations โ for the 95% of users who don't have a security gateway. Install Lens โ
Why AegisGate?
Every AI interaction is an attack surface. Prompt injections leak secrets. MCP servers exfiltrate context. A2A agents escalate privileges across trust boundaries. A single misconfigured LLM response can expose PII, violate compliance, or hand an attacker a credential.
AegisGate sits in front of all of it โ one binary, zero dependencies, fail-closed by default.
- Sub-millisecond overhead. 3.2ms p95 at 24K+ RPS. Your users won't notice it's there.
- Fail-closed. If AegisGate can't scan a response, it blocks it. No silent failures, no pass-through on error.
- Self-hosted. No API keys to rotate, no third-party to trust. Your data stays in your infrastructure.
- 6 pillars, one gateway. HTTP, MCP, A2A, ACP, RESPONSE, and Trust โ no patchwork of point products.
- 153 detection patterns. Secrets, XSS, PII, and compliance โ wired into every response, every time.
- Red-team hardened. 26/27 adversarial tests pass. TRACE methods rejected. All security headers present. No
unsafe-evalin CSP.
Security Posture
| Metric | Value |
|---|---|
| CVEs | 0 |
| Red team tests passed | 26 / 27 |
| Fail-closed by default | โ |
| TRACE/CONNECT/TRACK blocked | โ |
| Security headers (CSP, CORP, COEP, COOP, HSTS) | โ |
| Private keys in git | 0 (rotated, gitignored, pre-commit blocked) |
| Code-scanning alerts open | 0 |
| Dependabot alerts open | 0 |
Request Flow
flowchart LR
Client["๐ค Client / Agent"] -->|"HTTP ยท MCP ยท A2A"| Gateway["๐ก๏ธ AegisGate"]
subgraph Pillars["6 Protection Pillars"]
direction TB
HTTP["HTTP API<br/>pkg/response/"]
MCP["MCP<br/>pkg/mcpserver/"]
A2A["A2A<br/>pkg/a2a/"]
ACP["ACP<br/>pkg/acp/"]
RESP["RESPONSE<br/>pkg/response/detectors/"]
TRUST["Trust<br/>pkg/attestation/"]
end
Gateway --> Pillars
Pillars -->|"Scanned โ
"| LLM["๐ค LLM / AI Service"]
Pillars -->|"Blocked โ"| Client
LLM -->|"Response"| Gateway
Gateway -->|"Clean"| Client
Gateway -->|"Sanitized / Rejected"| Client
subgraph Infra["Infrastructure"]
PG[("PostgreSQL<br/>persistence")]
Redis[("Redis<br/>rate limiting")]
end
Gateway --- Infra
Detection Engine
The pkg/response/detectors/ package provides 153 regex patterns with full Lens parity:
| Category | Patterns | What it catches |
|---|---|---|
| Secrets | 45 | AWS keys, GitHub PATs, Stripe keys, JWTs, GitLab tokens, Twilio, SendGrid, private keys |
| XSS | 12 | <script>, event handlers, javascript:, SVG-based, encoded variants |
| PII (US Core) | 15 | SSN, phone, DOB, MRN, ZIP+4, full names with context |
| PII (Extended) | 13 | Email, IP addresses, passport numbers, driver's licenses |
| PII (International) | 9 | National IDs (NHS, SIN, TFN, IRD, BSN, CF, SSN-IT, NRIC, MyNumber) |
| PII (Financial) | 24 | Credit cards, IBANs, SWIFT/BIC, routing numbers |
| Compliance | 35 | GDPR data types, HIPAA PHI indicators, PCI-DSS card data, CCPA personal info |
import "github.com/aegisgatesecurity/aegisgate-platform/pkg/response/detectors"
// Scan all 153 patterns
matches := detectors.DetectAll(text)
// Scan by category
secrets := detectors.DetectSecrets(text)
xss := detectors.DetectXSS(text)
pii := detectors.DetectPIIUSCore(text)
compliance := detectors.DetectCompliance(text)
// Wired into ResponseGuard (default: enabled)
guard := response.NewResponseGuard()
result, _ := guard.Scan(ctx, text)
// result.DetectedXSS, result.DetectedCompliance, result.DetectedPII, result.DetectedSecrets
How AegisGate Compares
| Capability | AegisGate | Generic AI Firewalls |
|---|---|---|
| HTTP API scanning | โ Native | โ |
| MCP guardrails | โ Native | โ Plugin or missing |
| A2A protocol security | โ Native | โ Not supported |
| ACP enforcement | โ Native | โ Not supported |
| Response scanning (153 patterns) | โ Built-in | โ ๏ธ Limited or external |
| Cryptographic attestation | โ Native | โ Not available |
| Self-hosted, zero dependencies | โ Single binary | โ Requires external services |
| Fail-closed by default | โ | โ ๏ธ Often fail-open |
| 15+ compliance frameworks | โ | โ ๏ธ 3โ5 typical |
| PostgreSQL + file persistence | โ | โ ๏ธ Cloud-locked |
| HA clustering | โ Native | โ ๏ธ Enterprise add-on |
| Open source (Apache 2.0) | โ | โ Proprietary |
v3.5.0 Highlights
| Feature | Description |
|---|---|
| FedRAMP 151/170 Automated (88.8%) | Compliance Engine v2: 69 controls promoted from manual/stub to real CheckFuncs. 19 remaining are customer-responsibility. |
| gRPC Service Layer | 7 services, 50 RPCs with health checking, reflection, and TLS |
| Trust API Attestation | Cryptographic attestation generation and verification (RFC 3161 TSA) |
| SIEM Promotion | Real event forwarding to Splunk/Datadog/ELK (no longer a stub) |
| SSO Persistence | PostgreSQL-backed OIDC session storage with TTL and ACR value mapping |
| Token Analytics | Per-request token usage metrics wired into the request pipeline |
| PDF Export | Questionnaire results export to formatted PDF with scoring and evidence citations |
| 153-Pattern Detection Engine | Full Lens parity: 45 secrets, 12 XSS, 15+13+9+24 PII, 35 compliance patterns |
| PostgreSQL Persistence | 6 integration test suites (107 tests) via testcontainers-go |
| HA Clustering | Multi-node deployments with distributed rate limiting, instance identity, and health checks |
| Security Hardening | 5 auth bypass fixes, localhost-only metrics, CSP hardening. 26/27 red team tests pass |
6 Pillars
| Pillar | Package | Description |
|---|---|---|
| HTTP API | pkg/response/ |
Request/response scanning, PII redaction, secret masking |
| MCP | pkg/mcpserver/ |
Model Context Protocol guardrails |
| A2A | pkg/a2a/ |
Agent-to-Agent protocol security |
| ACP | pkg/acp/ |
Agent Capability Policy enforcement |
| RESPONSE | pkg/response/detectors/ |
153-pattern detection (secrets, XSS, PII, compliance) |
| Trust Framework | pkg/attestation/, pkg/trust/ |
Cryptographic attestation, CISO posture digest |
Compliance Coverage
| Framework | Controls | Package |
|---|---|---|
| EU AI Act | 82 | pkg/compliance/eu-ai-act/ |
| FedRAMP (NIST 800-53) | 170 (151 automated) | pkg/compliance/fedramp/ |
| SOC 2 Type II | 5 | pkg/compliance/soc2/ |
| ISO 27001 | 14 | pkg/compliance/iso27001/ |
| HITRUST CSF | 6 | pkg/compliance/hitrust/ |
| TISAX | 7 | pkg/compliance/tisax/ |
| CMMC Level 2 | 14 | pkg/compliance/cmmcl2/ |
| NIST 800-171 | 14 | pkg/compliance/nist800171/ |
| FIPS 140-2 | 11 | pkg/compliance/fips/ |
| NIST AI RMF | 8 | pkg/compliance/nist_ai_rmf/ |
| CCPA | 7 | pkg/compliance/ccpa/ |
| HIPAA | 11 | pkg/compliance/hipaa/ |
| PCI-DSS | 12 | pkg/compliance/pci/ |
Quick Start
# Build
go build -o aegisgate ./cmd/aegisgate-platform
# Run with defaults (in-memory stores)
./aegisgate
# Run with PostgreSQL
export DATABASE_URL="postgres://user:pass@localhost:5432/aegisgate"
./aegisgate
# Run integration tests (requires Docker)
go test -tags=integration -timeout 300s ./pkg/ioc/... ./pkg/persistence/...
Architecture
cmd/aegisgate-platform/ # Binary entry point
pkg/
โโโ a2a/ # Agent-to-Agent security
โโโ acp/ # Agent Capability Policy
โโโ attestation/ # Cryptographic envelope (Sign/Verify/VerifyWithKey/VerifyOnline)
โโโ audit/soc2/ # SOC 2 evidence collection
โโโ compliance/ # 15+ framework modules
โโโ cluster/ # HA clustering & distributed rate limiting
โโโ correlation/ # Event correlation engine
โโโ cve/ # CVE-for-AI feed
โโโ detectors/ # 153-pattern detection engine
โโโ evaluator/ # Adversarial benchmark suite
โโโ ioc/ # IOC management
โโโ mcpserver/ # MCP guardrails
โโโ persistence/ # Storage backends (file + PostgreSQL)
โโโ rbac/ # Role-based access control
โโโ response/ # 6-pillar response guard
โโโ trust/ # Trust Framework (6 sub-packages)
โโโ testdb/ # Shared testcontainers infrastructure
Testing
# Unit tests (99 packages)
go test ./...
# Integration tests (6 PostgreSQL packages, requires Docker)
go test -tags=integration -timeout 300s ./pkg/ioc/... ./pkg/persistence/... ./pkg/rbac/... \
./pkg/license/... ./pkg/correlation/... ./pkg/attestation/...
# Coverage
go test -coverprofile=coverage.out ./...
go tool cover -func=coverage.out | grep total
License
Apache 2.0 โ see LICENSE.
Security
See SECURITY.md for vulnerability reporting. See govulncheck.toml for the GO-2026-5932 suppression (openpgp transitive, not called).
๐ AegisGate Security ยท โ๏ธ [email protected]
Made with ๐ค by AegisGate Security developers to secure the AI attack surface.
Yorumlar (0)
Yorum birakmak icin giris yap.
Yorum birakSonuc bulunamadi