Deploy, enrol, connect, operate
Everything you need to take AegisWire from a first device to a multi-site federated fleet — one post-quantum transport, one control plane, gateways wherever your data has to live. Start with the orientation below, then jump to the area you need.
Orientation
How AegisWire fits together
Three components make up every deployment. Your tenant is provisioned as a managed service, so you operate the parts that matter to you and we operate the rest — with the same trust architecture end to end.
Your managed tenant
A dedicated control plane issues device identities, signs admission grants and policy, and enforces your licence and entitlements. You administer users, devices, gateways, tokens, and policy from its admin console.
The data plane
Gateways terminate the quantum-resistant tunnel and forward traffic under centrally enforced policy. Run them on AWS or Vultr — one tenant can mix both, with no vendor lock-in. Turnkey site-to-site links join two gateways directly across regions.
How traffic enters
Endpoints connect through the native apps, or embed the transport directly with the developer SDK. Both enrol with a one-time activation token and negotiate the same post-quantum handshake.
Quick start
Connect your first device
Get your tenant
Your AegisWire control plane is provisioned and handed over with admin access. Talk to us to start.
Issue a token
From the admin console, mint a one-time activation token for a user or device. The token carries no secrets — scope is derived server-side.
Enrol the client
Install the native app, paste the token, and enrol. The device generates its own key material and receives a signed identity and gateway contact points.
Connect
Hit connect. The client completes the post-quantum handshake against a gateway and carries your traffic under enforced policy — with a fail-closed kill-switch if trust ever breaks.
Native clients
Native clients on macOS, iOS, Linux, Windows, and Android, all on the same post-quantum engine. Version-matched install and operator guides ship with your tenant onboarding.
Reference
Explore by area
Enterprise VPN
Zero-trust access for your workforce: identity-bound devices, centrally enforced split-tunnel policy, and a self-healing post-quantum tunnel.
Site-to-Site networking
Turnkey multi-region federation: join two gateways with a deny-by-default trust link running the same quantum-resistant cipher suite as client sessions — no flags, no manual key exchange.
Developer SDK & API
Embed the post-quantum transport directly in your own applications and devices. Token-metered and monthly-call packages, staff-provisioned with your tenant.
AI Sentinel
Licensed Add-OnA separately-licensed plugin: entity-graph and temporal detectors with device-posture admission, applied across post-quantum sessions with full audit traceability.
Secure transport
The transport layer underneath everything: hybrid post-quantum key establishment, per-session ratcheting, BLAKE3 STREAMHEAL, and authenticated encryption.
Deployment models
Where gateways and control planes run — region, cloud, and account boundaries across AWS and Vultr — and how to keep them inside your residency requirements.
Security & crypto model
The algorithms in use, the trust model, key lifecycle, signed update distribution, and audit guarantees — the basis for security review and procurement.
Architecture whitepaper
The full technical architecture, trust model, and evidence bundle. Suited to CISOs, security architects, and procurement teams.
Security FAQ & disclosure
Honest answers on certifications, testing, and data handling — plus how to report a vulnerability responsibly.
The moat
One cipher suite, every session
AWT_UNIFIED is the post-quantum transport underneath the apps, the SDK, and every site-to-site link. The same hybrid handshake protects a phone on hotel Wi-Fi and a federated link between two regions — there is no weaker fallback path to attack.
- Built to the controls these audits examine. Engineered against the change-control, least-privilege, traceability, and isolation expectations of SOC 2, ISO 27001, GDPR, and HIPAA-style review.
- Signed update distribution. Releases are cryptographically signed; clients verify before applying.
- Fail-closed by design. If admission or policy can't be verified, the tunnel stays shut — no silent fallback.
Post-quantum cryptography
The primitives behind every session
Delivered with onboarding
Operator runbooks & API reference
Detailed operator runbooks, the SDK/API reference, and enrolment integration guides are version-matched to your tenant and provided as part of onboarding so they always reflect the exact build you run. If you need access ahead of provisioning, or have an integration question, reach the engineering team directly.
Talk to engineering
Request an architecture briefing
A technical walkthrough of the transport, trust model, and deployment options — mapped to your environment and procurement requirements.