πŸ›‘οΈ AegisGate Security Platformβ„’ β€” Secure Every AI Interaction

The only AI security gateway with five pillars of AI security (HTTP API, MCP, A2A, RESPONSE, Trust Framework), MITRE ATLAS enforcement, the EU AI Act Compliance Module, and zero external dependencies. Deploy in 60 seconds.

Version Go Security Coverage Docker
"One platform. Complete AI security. From HTTP APIs to agent communication."
European Union flag NEW in v3.3.0-beta.2: The EU AI Act Compliance Module β€” 82 controls across 8 categories of EU Regulation 2024/1689, included with Professional+ tier. Read the release notes β†’

AegisGate Security Platform secures every AI interaction point with five pillars: HTTP API scanning, MCP protocol protection, A2A agent-to-agent verification, real-time response scanning, and the Trust Framework (v3.2.0) β€” continuous, cryptographically-signed trust scoring for every AI interaction. The EU AI Act Compliance Module (v3.3.0) adds 82 controls for EU AI Regulation 2024/1689, included with Professional+ tier.

🌐 HTTP API Security

  • 144+ detection patterns
  • MITRE ATLAS 66 techniques
  • PII, secrets, API key detection
  • Bidirectional request/response scanning

πŸ”— MCP Protocol Protection

  • Session authentication + isolation
  • 8 guardrails active
  • MITRE ATLAS enforcement
  • Tool authorization with risk matrix

🀝 A2A Agent-to-Agent Security

  • mTLS + HMAC-SHA256 integrity
  • Capability enforcement per agent
  • License-aware enforcement
  • Rate limiting and audit logging

πŸ›‘οΈ Agent Response Security

  • PII, secrets, hallucination, toxicity detection
  • Fail-closed by default
  • Redaction with multiple strategies
  • Compliance reports (GDPR, HIPAA, PCI, SOC 2)

πŸ” Trust Framework NEW in v3.2.0

  • Per-session trust score accumulator
  • Ed25519-signed attestations on every event
  • Cross-pillar correlation (MCP, A2A, Proxy, Response)
  • Professional+ tier feature
  • Read scores via GET /api/v1/trust/score


Why AegisGate?

There are other AI security products. Here’s how AegisGate compares on the dimensions that matter to enterprise security teams:

CapabilityAegisGateLakera GuardNeMo GuardrailsRebuffProtect AI
Deployment modelSelf-hosted single binarySaaS API onlyLibrary (in-app)Library (in-app)Platform
HTTP proxy scanningβœ…βœ…βŒβŒβš οΈ
MCP protocol protectionβœ…βŒβŒβŒβŒ
A2A protocol protectionβœ…βŒβŒβŒβŒ
ACP protocol protectionβœ…βŒβŒβŒβŒ
Response-side scanningβœ…βœ…βœ…βœ…βœ…
Trust Framework (attestations)βœ… Ed25519-signed❌❌❌⚠️
MITRE ATLAS coverageβœ… 66 techniques⚠️ Partial❌⚠️ Partialβœ…
OWASP LLM Top 10βœ… 49 patternsβœ…βœ…βœ…βœ…
European Union flag EU AI Act controlsβœ… 82 controls❌❌❌❌
Multi-framework complianceβœ… 10 frameworks❌❌❌⚠️
Tamper-evident audit logsβœ… Hash chain + RFC 5424❌❌❌⚠️
Open sourceβœ… Apache 2.0βŒβœ… Apache 2.0βœ… MIT❌
Air-gap deployableβœ… Single binaryβŒβœ… Libraryβœ… Library❌
Hardware footprint13.3 MB binary, < 256 MB RAMn/a (SaaS)In-processIn-processn/a (platform)

TL;DR: If you need protocol-level security (MCP, A2A, ACP) + compliance evidence + self-hosting, AegisGate is the only option that covers all three.

  • Library-style tools (NeMo Guardrails, Rebuff) are great for in-app alignment but don't protect your network boundary
  • SaaS tools (Lakera) require sending your traffic to a third party
  • Compliance-focused tools (Protect AI) are platforms, not gateways, and don't include protocol coverage

Attack Surface Coverage

Your AI infrastructure spans multiple attack surfaces. Most security tools only cover one or two. AegisGate covers all six:

Attack SurfaceRiskTraditional WAFsLLM Alignment ToolsAegisGate
HTTP APIsPrompt injection, data leakage, PII exposure⚠️ AI-agnostic❌ Noβœ… AI-aware scanning, 144+ patterns
MCP ProtocolTool poisoning, session hijacking, supply-chain attacks❌ No native protection❌ Noβœ… Built-in protocol guard, 8 guardrails
A2A CommunicationAgent impersonation, data tampering, capability escalation❌ No native protection❌ Noβœ… mTLS, HMAC, capability enforcement
Agent ResponsePII leakage, secret exposure, hallucination, toxicity❌ No native protection⚠️ Someβœ… Real-time response guard, 5 detectors
ACP ProtocolMessage tampering, capability escalation, replay attacks❌ No native protection❌ Noβœ… HMAC-signed messages
Trust / AuditNo traceability of agent behavior across protocols❌ No native protection❌ Noβœ… Ed25519-signed attestations

AegisGate fills these gaps with a single unified platform.

AegisGate secures all six in a single 13.3 MB binary you deploy in 60 seconds.


Five Pillars in Detail

🌐 HTTP Proxy Security

Bidirectional scanning of every API request and response. 144+ patterns detect secrets, PII, and threats before they reach your AI services.

πŸ”— MCP Protocol Protection

Session authentication, tool authorization, and 8 guardrails protect your AI agents from supply chain attacks and unauthorized tool execution.

🀝 A2A Agent-to-Agent Security

Zero-trust guardrails for inter-agent communication. mTLS authentication, HMAC integrity, capability enforcement, and license-aware rate limiting.

πŸ” ACP Protocol Security

HMAC-signed messages, per-session rate limiting, and response scanning protect agent communication from tampering and replay attacks.

πŸ›‘οΈ Agent Response Security

Real-time scanning of LLM outputs for PII, secrets, hallucination, and toxicity. Fail-closed security protects sensitive data.

⚑ Rate Limiting & Throttling

Protect your AI infrastructure from abuse with intelligent rate limiting. Per-client, per-IP, and per-model quotas prevent DoS attacks and manage costs.

πŸ” Threat Intelligence

Real-time threat detection with pattern matching across 144+ signatures. Blocks prompt injection, sensitive data exfiltration, and adversarial attacks.

πŸ“Š Full Observability

Every AI request, response, tool call, and session is logged. SIEM-ready with structured JSON output and compliance reports.


European Union flag EU AI Act Compliance Module (NEW in v3.3.0) β€” Included with Professional+ tier

The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive AI regulation. AegisGate’s EU AI Act Compliance Module gives you a single source of truth for whether your AI system is compliant β€” across 82 controls in 8 categories.

πŸ“Š

82 controls, 8 categories

  • Prohibited Practices (Article 5)
  • Risk Management (Article 9)
  • Data Quality (Article 10)
  • Technical Documentation (Articles 11+12)
  • Record-Keeping (Articles 13+14)
  • Human Oversight (Article 15)
  • Accuracy, Robustness, Cybersecurity (Articles 51–55)
  • Annex IV Technical Documentation (AI-*)
🎯

Who needs it

  • AI providers placing high-risk AI systems (Annex III) on the EU market after August 2026
  • Deployers of AI in employment, education, law enforcement, critical infrastructure
  • GPAI model providers with > 10²⁡ FLOPs of training compute
  • EU + non-EU companies placing AI on the EU market
βš™οΈ

How it works

  • 9 automatic controls β€” AegisGate enforces these in-line (input validation, data quality, log retention, etc.)
  • 73 manual controls β€” AegisGate provides checklists, evidence templates, audit-ready reports
  • Compliance scan endpoint: GET /api/v1/compliance/scan?framework=eu-ai-act returns coverage %, missing modules, remediation steps
  • Full audit report: GET /api/v1/compliance/report?framework=eu-ai-act returns all 82 controls with status
πŸ’Ό

Tier & pricing

  • Tier gate: Professional+ (Professional and Enterprise)
  • Pricing: Included with Professional and Enterprise at no extra cost
  • BAA + DPA: standard agreements cover EU AI Act data flows (see /legal/)
  • Read the customer 1-pager: EU AI Act overview
European Union flag EU AI Act Module β€” Full Details

Beta status: This module is fully implemented and tested in v3.3.0-beta.2. Counsel review of the legal interpretation is pending (v3.4.0+). Use for evaluation and pre-audit work; defer formal conformity assessment until counsel sign-off is complete.


Compliance Frameworks

Choose the coverage that matches your compliance needs.

FrameworkCommunityStarterDeveloperProfessionalEnterprise
MITRE ATLASβœ“βœ“βœ“βœ“βœ“
NIST AI RMFβœ“βœ“βœ“βœ“βœ“
OWASP LLM Top 10βœ“βœ“βœ“βœ“βœ“
ISO 27001βœ“βœ“βœ“βœ“βœ“
GDPRβ€”Viewβœ“βœ“βœ“
HIPAAβ€”β€”βœ“βœ“βœ“
PCI-DSSβ€”β€”βœ“βœ“βœ“
SOC2 Type IIβ€”β€”Moduleβœ“βœ“
ISO 42001 (AI)β€”β€”β€”βœ“βœ“
European Union flag EU AI Actβ€”β€”β€”βœ“ Includedβœ“ Included

Starter tier adds SSO, RBAC, and GDPR view for SMB/SLED/SOHO teams. Developer tier adds full compliance and mTLS. Professional includes everything plus the EU AI Act Module at no extra cost. Enterprise adds custom frameworks and dedicated support.


Quick Start

# Pull and run
docker run -d \
  -p 8080:8080 \
  -p 8081:8081 \
  -p 8443:8443 \
  ghcr.io/aegisgatesecurity/aegisgate-platform:v3.3.0-beta.2
# Verify deployment
curl http://localhost:8443/health

By the Numbers

144+
Detection Patterns
66
MITRE ATLAS Techniques
82
European Union flag EU AI Act Controls
24,806
Peak RPS (v3.1.1 bench)
3.2ms
Avg Latency (v3.1.1 bench)
5
Security Pillars +Trust
10
Compliance Frameworks
97.8%
Test Coverage
5,484
Tests Passing
13.3 MB
Binary Size

Enterprise Security Features

πŸ” Cryptographic Identity

ECDSA P-256 agent identity and verification. Challenge-response authentication with key rotation support.

πŸ›‘οΈ Fail-Secure Design

Insecure fallback replaced with fail-closed behavior. All security checks are fail-closed by default.

πŸ“‹ STRIDE Threat Model

Comprehensive threat analysis covering spoofing, tampering, repudiation, information disclosure, DoS, and elevation of privilege.

πŸ”„ Cross-Protocol Correlation

Correlate threats across HTTP, MCP, A2A, ACP, and ANP protocols with real-time pattern matching.