Scope
Define the service, lifecycle, exposure, criticality, and data context.
Evaluating Risk. Informing Decisions.
Aegis101 combines guided scope, dynamically routed questions, progressive reporting, and prioritised actions to move assessment work from scattered inputs to decision-ready direction.
Aegis101 provides answer-based risk interpretation and decision support. It does not replace audit, certification, evidence validation, or accountable risk judgement.
From context to action
Aegis101 brings scope, assessment logic, risk interpretation, ownership direction, and reassessment into one coherent workflow.
Define the service, lifecycle, exposure, criticality, and data context.
Follow dynamically routed questions with plain-language guidance.
Save automatically, resume later, and defer information that is not yet available.
Generate an interim or completed position without disguising uncertainty.
Focus owners on treatment, evidence, decisions, and outstanding confirmation.
Compare compatible reports and track change after remediation or review.
What you receive
Interim and completed reports show the current assessed position without hiding important exceptions or unavailable information. Category analysis and action roadmaps then connect findings to practical treatment.
Distinct risk domains
Security and Operability are not blended into a single generic score. Each domain keeps the concepts and language needed for credible risk decisions.
Assess exposure, control strength, material exceptions, treatment priorities, and the evidence needed to support closure. Security reporting does not publish impact as a separate score.
Assess supportability, recoverability, monitoring, change, resilience, and operational ownership. Service consequence is interpreted from context and described qualitatively.
Core Security and Operability logic provides the risk foundation: contextual routing, answer interpretation, prioritisation, remediation direction, and reassessment.
Frameworks are added through governed, framework-specific mappings and language. NCSC CAF v4 is the first implementation, presented as a mapped screening view and direction for further review, not a formal CAF assessment.
Register your interest to discuss Security, Operability, framework-specific reporting, or a controlled evaluation of Aegis101.