Define scope
Capture lifecycle, criticality, exposure, data, hosting, and service context.
Risk assessment and reporting
Aegis101 uses guided scope and contextual routing to identify material weaknesses quickly, keep unresolved information visible, and turn the assessed position into a prioritised action plan.
Outputs inform accountable decisions. Answers and supporting evidence remain subject to owner review and independent validation where required.
The assessment lifecycle
The assessment route responds to the system or service context, reducing irrelevant questioning while preserving the controls needed for credible interpretation.
Capture lifecycle, criticality, exposure, data, hosting, and service context.
Ask relevant questions and explain what each one is seeking and why it matters.
Autosave progress, save explicitly, and continue the assessment across working sessions.
Interpret the available answer basis in an interim or completed report.
Complete exact outstanding items and direct treatment, evidence, or decision follow-up.
Reassess, compare compatible reports, and understand directional change over time.
Decision-ready output
Each report layer has a purpose. It starts with status and decision context, moves through risk themes, and ends with practical follow-up and assurance boundaries.
Headline position, severity distribution, main drivers, priority risks, and the boundary of the decision.
Overall residual risk, distribution, material exceptions, and category-level interpretation.
Risk-led lanes, direct action focus, suggested ownership, and proportionate detail.
Highlights where review of supporting evidence would most improve confidence in the reported position. Aegis101 does not independently validate evidence.
Governed mappings that retain the framework's structure, terminology, and limitations.
Clear decisions, follow-up, reassessment expectations, and assurance limitations.
Actionable by design
Roadmap actions preserve the relationship between the answered control, the risk it creates, and the evidence that would support an improved position.

Progressive by design
Not every control can be confirmed in one sitting. Aegis101 keeps unavailable information visible while using the confirmed answer basis to support proportionate risk decisions.
Autosave, explicit saving, Workspace drafts, and resume routes maintain continuity across assessment sessions.
Where the available basis supports reliable interpretation, generate a useful interim report without treating deferred or not-yet-confirmed items as positive answers.
Outstanding registers explain what remains and provide a direct route back to the relevant scope or control question.
Risk domains
A shared product experience does not require generic risk language. Aegis101 keeps the two non-functional domains distinct.
Focuses on threats, exposure, control gaps, material security findings, explicit treatment, and evidence for closure. Visible reporting avoids a separate impact score.
Focuses on operating ownership, monitoring, recoverability, capacity, change, and continuity. Consequence is derived from service context and explained in plain language.
Assessment workspace
The authenticated Workspace retains drafts, reports, creator provenance, reassessment history, compatible comparison, and trend interpretation.
Explore the fictional Core and framework-specific report tours, then register interest to discuss fit, evaluation, and the outputs that matter to your organisation.