Documentation

Deploy, enrol, connect, operate

Everything you need to take AegisWire from a first device to a multi-site federated fleet — one post-quantum transport, one control plane, gateways wherever your data has to live. Start with the orientation below, then jump to the area you need.

Full CNSA 2.0 suite (US NSA) · UK NCSC-aligned — every customer, every packet
6 Integrated Components
Single Trust Architecture
Transport
Core Layer
Control
Plane
Gateway
Fabric
VPN
Services
Trust
Operations
Admin
Interface
Quantum-Resistant Encryption
Centrally Managed Policies
Automated Certificate Management
Privacy-Preserving Operational Telemetry

Orientation

How AegisWire fits together

Three components make up every deployment. Your tenant is provisioned as a managed service, so you operate the parts that matter to you and we operate the rest — with the same trust architecture end to end.

1 · Control plane

Your managed tenant

A dedicated control plane issues device identities, signs admission grants and policy, and enforces your licence and entitlements. You administer users, devices, gateways, tokens, and policy from its admin console.

2 · Gateways

The data plane

Gateways terminate the quantum-resistant tunnel and forward traffic under centrally enforced policy. Run them on AWS or Vultr — one tenant can mix both, with no vendor lock-in. Turnkey site-to-site links join two gateways directly across regions.

3 · Clients & SDK

How traffic enters

Endpoints connect through the native apps, or embed the transport directly with the developer SDK. Both enrol with a one-time activation token and negotiate the same post-quantum handshake.

Quick start

Connect your first device

1

Get your tenant

Your AegisWire control plane is provisioned and handed over with admin access. Talk to us to start.

2

Issue a token

From the admin console, mint a one-time activation token for a user or device. The token carries no secrets — scope is derived server-side.

3

Enrol the client

Install the native app, paste the token, and enrol. The device generates its own key material and receives a signed identity and gateway contact points.

4

Connect

Hit connect. The client completes the post-quantum handshake against a gateway and carries your traffic under enforced policy — with a fail-closed kill-switch if trust ever breaks.

Native clients

Native clients on macOS, iOS, Linux, Windows, and Android, all on the same post-quantum engine. Version-matched install and operator guides ship with your tenant onboarding.

Clients macOS iOS Linux Windows Android

Reference

Explore by area

Enterprise VPN

Zero-trust access for your workforce: identity-bound devices, centrally enforced split-tunnel policy, and a self-healing post-quantum tunnel.

Site-to-Site networking

Turnkey multi-region federation: join two gateways with a deny-by-default trust link running the same quantum-resistant cipher suite as client sessions — no flags, no manual key exchange.

Developer SDK & API

Embed the post-quantum transport directly in your own applications and devices. Token-metered and monthly-call packages, staff-provisioned with your tenant.

AI Sentinel

Licensed Add-On

A separately-licensed plugin: entity-graph and temporal detectors with device-posture admission, applied across post-quantum sessions with full audit traceability.

Secure transport

The transport layer underneath everything: hybrid post-quantum key establishment, per-session ratcheting, BLAKE3 STREAMHEAL, and authenticated encryption.

Deployment models

Where gateways and control planes run — region, cloud, and account boundaries across AWS and Vultr — and how to keep them inside your residency requirements.

Security & crypto model

The algorithms in use, the trust model, key lifecycle, signed update distribution, and audit guarantees — the basis for security review and procurement.

Architecture whitepaper

The full technical architecture, trust model, and evidence bundle. Suited to CISOs, security architects, and procurement teams.

Security FAQ & disclosure

Honest answers on certifications, testing, and data handling — plus how to report a vulnerability responsibly.

The moat

One cipher suite, every session

AWT_UNIFIED is the post-quantum transport underneath the apps, the SDK, and every site-to-site link. The same hybrid handshake protects a phone on hotel Wi-Fi and a federated link between two regions — there is no weaker fallback path to attack.

  • Built to the controls these audits examine. Engineered against the change-control, least-privilege, traceability, and isolation expectations of SOC 2, ISO 27001, GDPR, and HIPAA-style review.
  • Signed update distribution. Releases are cryptographically signed; clients verify before applying.
  • Fail-closed by design. If admission or policy can't be verified, the tunnel stays shut — no silent fallback.
Commissioned on customer scope

Post-quantum cryptography

The primitives behind every session

Hybrid key exchange
Quantum-safe + classical, combined
ML-KEM-1024X25519
Identity signatures
Post-quantum signed trust chains
ML-DSA-87
Record encryption
Authenticated, per-session keys
AES-256-GCM
Keyed hashing · STREAMHEAL
Integrity and rapid rekey
BLAKE3
Implements US NSA CNSA 2.0 in full · aligned with UK NCSC post-quantum guidance

Delivered with onboarding

Operator runbooks & API reference

Detailed operator runbooks, the SDK/API reference, and enrolment integration guides are version-matched to your tenant and provided as part of onboarding so they always reflect the exact build you run. If you need access ahead of provisioning, or have an integration question, reach the engineering team directly.

Talk to engineering

Request an architecture briefing

A technical walkthrough of the transport, trust model, and deployment options — mapped to your environment and procurement requirements.

Implements US NSA CNSA 2.0 in full · aligned with UK NCSC post-quantum guidance