Redvia SystemsAegisCore
AegisCore v1.5.19 · released 2026-05-15

Your SOC.
Your servers.
Your evidence.

A local-first, self-hosted security operations platform. Red team, blue team, decision intelligence, SIEM/SOAR and forensic-grade evidence — in one air-gappable deployment that never phones home.

Runs entirely on your infrastructureAir-gappable — no mandatory cloudZero-terminal operator experience
AegisCore Operator Consoleruntime ready
Red Team
140tools online
scope enforced · kill-switch armed
Blue Team
3,862detection rules
3,132 Sigma · 730 YARA
Evidence
Ed25519chain verified
SHA-256 · NIST 800-86
14:02:11 pentest-sim — 49/49 vectors blocked
14:02:09· evidence-chain — block #1847 sealed (sha256 ✓)
14:02:04· decision-engine — risk score recomputed · deterministic
140
Integrated offensive tools
3,132
Sigma detection rules
730
YARA rules
49 / 49
Attack vectors blocked in pentest sim
6,588
Automated tests passing
165
Signed release proof artifacts
Why local-first

The cloud-first SOC has three structural problems

AegisCore exists because the dominant model for security operations is misaligned with how regulated organisations actually need to work.

Problem 01

Per-GB pricing punishes visibility

Ingestion-based licensing means the more you monitor, the more you pay. Teams end up dropping log sources to control cost — the opposite of what security needs. AegisCore charges a flat per-tier price; ingest everything.

Problem 02

Cloud-only tools fail when the cloud does

A SaaS SOC platform is a single point of failure and a data-sovereignty problem for regulated environments. AegisCore runs entirely on your own servers and degrades gracefully — it never hard-depends on a remote service.

Problem 03

LLM assistants hallucinate in the decision path

A language model that invents a CVE or a metric is unacceptable when an auditor is reviewing why an IP was blocked. AegisCore's Decision Engine is fully deterministic — every conclusion is reproducible and explainable.

Eight pillars, one deployment

A complete security operations centre

Most vendors sell you one or two of these and integrate the rest. AegisCore ships all eight in a single installer — designed to work together, audited together, released together.

From download to running SOC

Three steps. No terminal at any point.

AegisCore is built to be deployed by the people who will operate it — not only by the engineers who installed it.

1

Download one installer

A single full-offline package per platform — engine, 140 tools, all detection rules and local AI bundled. No separate dependencies, no package manager, no terminal.

~6 GB · Linux / Windows / macOS

2

Activate in the first-run wizard

Paste a Professional, Team or Enterprise key — or skip and run the full Community trial. The same installer covers every tier; activation decides what unlocks.

Online or air-gapped envelope

3

Operate from the console

The runtime works in the background. Every action — red team runs, detections, playbooks, evidence export — happens in the Operator UI. Operators never touch a shell.

67-page operator console

How it compares

Where AegisCore sits in the market

A factual comparison against the platforms regulated buyers most often evaluate. Positioning reflects publicly documented product behaviour.

CapabilityAegisCoreSplunk ESCrowdStrikeWazuh
Deployment modelLocal-first, air-gappableCloud-first directionCloud-onlySelf-hosted
Pricing modelFlat per-tierPer-GB ingestedPer-endpointFree / paid support
Offensive + defensive in oneYes — 8 pillarsDefensive onlyDefensive onlyDefensive only
Decision layerDeterministic, no LLMLLM assistantLLM assistantNone
Evidence chainEd25519 + SHA-256, NIST 800-86Log retentionCloud retentionLog retention
Commercial supportAll paid tiersEnterpriseEnterpriseSeparate contract

Comparison reflects publicly documented product positioning as of 2026. Vendor names are trademarks of their respective owners.

Download the full platform. No signup.

The Community edition is the complete AegisCore build — 140 tools, 3,862 detection rules, local AI, all eight pillars. Run it on your own hardware in minutes.