Unified Security Platform

One platform for detection, governance, identity and operations.

Aegis brings SIEM & SOAR, GRC, identity governance, privileged access, OT security and offensive testing onto a shared core — so the same asset, the same user and the same control mean the same thing everywhere.

UnifiedShared identity, assets and evidence
NCAECC · DCC · CCC · OTCC frameworks
IT + OTConverged coverage
On-premiseDeployed in your own data centre
Products

One security operating model.

Each product stands alone. Together they share identity, assets, evidence and workflow — no duplicate inventories, no reconciliation projects.

🛡️

Aegis SIEM & SOAR

Detection · Response

AI-assisted detection and correlation with automated containment. Investigations move from alert to action without leaving the console.

  • Correlation, UEBA and threat intelligence
  • SOAR playbooks with live containment actions
  • Vulnerability management and compliance reporting
  • OT digital twin for process-aware detection
📋

Aegis GRC

Governance · Risk · Compliance

Compliance and risk management built around the controls regulators actually assess — with evidence, scoring and board-ready reporting.

  • NCA compliance assessment — ECC, DCC, CCC and OTCC
  • NIST SP 800-30 risk methodology
  • Cross-framework mapping and continuous monitoring
  • Third-party risk register and executive dashboards
👤

Aegis IAM

Identity Governance

Identity governance and administration across the joiner–mover–leaver lifecycle, with the evidence auditors ask for.

  • Lifecycle automation and role-based access
  • Access review and recertification campaigns
  • Segregation-of-duties and access risk scoring
  • Full audit trail of every entitlement change
🔑

Aegis PAM

Privileged Access

Controlled, recorded and time-bound access to critical systems — with the session itself as the audit record.

  • Multi-factor authentication and approval workflows
  • Session recording and forensic watermarking
  • Risk-based access decisions
  • Break-glass with enforced guardrails
🏭

Aegis OT

Industrial · ICS

Security for industrial control environments, built for engineers as much as analysts — passive by default, safe on live process networks.

  • OT asset discovery and lifecycle management
  • Purdue-model segmentation visibility
  • ICS protocol awareness and anomaly detection
  • Shared asset model with the SIEM
🎯

Aegis PenTest

Offensive Security

An engagement platform for penetration testing teams — from IP range to a finished, standards-aligned report.

  • Automated scoping-to-report workflow
  • NCA-standard report generation
  • AI-assisted finding write-up and triage
  • Findings feed straight into vulnerability management
🌐

Security Edge Gateway

Secure Access · Isolation

Remote access and browser isolation that keeps untrusted content off the endpoint entirely — users see pixels, never payloads.

  • Clientless RDP, SSH and VNC access
  • Remote browser isolation
  • Session brokering and policy enforcement
  • Recorded, reviewable access sessions
🗂️

Procedure Execution

Procedure Execution & Evidence

IT service management with regulatory gates built into the workflow, so compliance approval is part of the change — not a document after it.

  • Owner-routed control gate approvals
  • Change, incident and problem workflows
  • Approvals inbox for accountable owners
  • Evidence linked back to GRC controls
🧾

Aegis HR

System of Record

The authoritative employee record that drives identity. Joiners, movers and leavers start here and flow into IAM automatically.

  • Employee master data and org structure
  • Position, department and manager hierarchy
  • Lifecycle events published to identity
  • Clean separation from directory infrastructure
Architecture

Built on a shared platform core.

Modules are not bolted together after the fact. They are built on common entities, a common authentication layer and a common notification and reporting service.

Applications

Nine products, each independently deployable.

SIEM & SOARGRCIAM PAMOTPenTest Security EdgeProcedure ExecutionHR

Platform Core

Shared domain model and services used by every module.

Shared asset & identity entities Notification & alerting service Scheduled reporting Audit & evidence store

Enterprise Integration

Authenticates against your directory and connects to what you already run.

Active Directory / LDAP SSO & OIDC Just-in-time provisioning SMTP & ticketing Firewall & EDR response connectors

Deployment

Runs where your data has to stay.

On-premisesPrivate cloud ContainerisedAir-gap capable
Standards

Aligned to the frameworks you are measured against.

Controls, evidence and reporting are modelled on published frameworks rather than mapped to them afterwards.

Regulatory compliance — National Cybersecurity Authority

The frameworks Saudi organisations are assessed against. Controls, evidence and scoring are modelled on the published text.

ECC-2:2024Essential Cybersecurity Controls — assessment, evidence and scoring
DCC · CCC · OTCCData, cloud and operational technology controls, assessed through the same engine
Event Logs & MonitoringLog format, sources, retention and integrity — measured continuously against live data

Risk and security management

How risk is assessed and how the security programme is structured.

NIST SP 800-30Risk assessment methodology behind the risk register and treatment plans
ISO/IEC 27001Information security management alignment

Operational frameworks

Not compliance obligations — the working vocabulary the platform uses for detection and service management.

MITRE ATT&CKDetection rules carry technique IDs, so coverage can be measured against adversary behaviour
ITIL 4Change, incident and service management practices, with regulatory gates in the workflow
Product tour

See it in the console.

Screens from the running platform.

Aegis SIEM console
SIEM — SOC dashboard
Aegis GRC compliance dashboard
GRC — NCA ECC compliance posture
Aegis IAM access review
IAM — identity risk & access review
Aegis PAM session monitor
PAM — privileged session monitor
Aegis OT console
OT — asset estate & verification gates
Aegis PenTest dashboard
PenTest — engagement posture
Get in touch

Request a demonstration.

Tell us which modules matter most and we will arrange a walkthrough against your own use cases.

Direct contact

Prefer email? Reach us directly and we will reply within one business day.

✉️ info@aegisot.com

📍 Riyadh, Saudi Arabia