Aegis by Hatchery

AI security & governance

Governed access to Amazon Bedrock, from the coding tools your developers already use.

Developers sign in once with their work identity. From then on Claude Code, Codex CLI, Claude Desktop and any OpenAI-compatible tool reach Claude and GPT models on Amazon Bedrock through the Aegis gateway — every prompt inspected against a managed content policy and metered, with no API keys to copy, store or rotate, and no prompt content retained.

Prepaid usage. $50 a month per organization. Nothing to install on a server.

How it works

Aegis sits between the tools your developers already use and the models they want, and does the governance work that usually gets skipped because it gets in the way.

Sign in once, with your identity

Developers sign in with your organization's identity provider — Google Workspace today; yours federates in. A small local helper keeps the session fresh in the background. No static API keys exist anywhere. Disable a person upstream and their session expires within its token lifetime; there is no long-lived key to hunt down.

Keep your tools

One command, aegis init, points Claude Code, Codex CLI and any OpenAI-compatible SDK at the gateway, showing every change before it makes it and merging into the settings you already have. Claude Desktop takes one import inside the app. Nothing else changes about how anyone works.

Every request governed

Each request carries the developer's identity. A managed content policy covering harmful content and sensitive data inspects prompts before they reach the model and responses on the way back, and usage is metered per developer and per model, to the token — so usage, spend and policy events all have a name on them.

The models and tools your developers already like

Aegis adds governance to the tools people chose for themselves, rather than replacing them with one they did not.

Tools

  • Claude Code
  • Codex CLI
  • Claude Desktop
  • OpenAI SDKs
  • aider
  • anything OpenAI-compatible

Claude Code, Codex CLI and OpenAI-compatible clients are configured automatically. Claude Desktop needs one import inside the app, no administrator. Cursor is not supported yet. The ChatGPT desktop app cannot be pointed at Aegis — it signs in with a ChatGPT account rather than as an API client, and no setting changes that.

Governed models Tier 1

  • claude-opus-5most capable
  • claude-sonnet-5faster
  • claude-opus-4-8previous generation
  • claude-opus-4-7previous generation
  • claude-haiku-4-5small & fast
  • gpt-oss-120bopen-weight
  • gpt-oss-20bopen-weight

Prompts are inspected against the Aegis content policy before reaching the model, and blocked when they violate it. Model output is inspected the same way. Inspection is enforced by AWS in a separate account, so it cannot be turned off from the gateway. Prompt and completion content is not retained.

Zero data retention on Tier 1: the AWS account these models run in has its data-retention mode locked to none in every operating region, enforced in an account the gateway cannot edit.

Frontier OpenAI models Tier 2 — a different guarantee

  • gpt-5.6-solfrontier
  • gpt-5.6-terrafrontier
  • gpt-5.6-lunafrontier
  • gpt-5.5frontier
  • gpt-5.4frontier

Prompts are inspected against the Aegis content policy before reaching the model, and blocked when they violate it. Inspection is enforced by the gateway rather than by AWS, and model output is not inspected on this path. AWS retains requests and responses for up to 30 days for safety and abuse prevention, and does not share them with the model provider. We retain no prompt or completion content.

The Frontier OpenAI models run on a separate AWS surface where the enforcement that makes Tier 1 hold even against a compromised gateway does not exist, and where AWS keeps requests for up to 30 days. Same inspection, weaker enforcement, real retention — which is why Tier 2 is off by default and enabled per team by your administrator, with its own description wherever it appears.

Your IP is always yours

The prompts your developers write are your source code, your designs and your plans. Aegis is built so that they pass through, and nothing of them stays behind.

No prompt content retained by Aegis

Aegis retains no prompt, completion or tool-output content — not in a log, not in a database, in any environment. What is recorded is metadata: that a policy was violated, which type, by whom and when. Never the content that triggered it.

Zero data retention at AWS on Tier 1

On Tier 1 the AWS account the models run in has data retention locked to none in every operating region, so Amazon Bedrock keeps nothing either. Tier 2 is the documented exception, described separately above.

Enforcement that survives the gateway

On Tier 1, the content policy is attached to every model call by AWS identity and access management in a separate account that the gateway cannot edit. Even a compromise of the gateway itself could not switch inspection off.

Identity, not keys

Access is a short-lived token from your identity provider, refreshed by a helper on the developer's machine. There is no static key to leak, commit or forget to rotate. Card details are entered into fields hosted by the payment processor and never reach Aegis.

Every prompt and every response, inspected

Governance is only worth having if it covers all of the traffic, all of the time, and cannot be turned off by the thing it governs.

In and out, on every request

On Tier 1, 100% of prompts pass the managed content policy before they reach the model, and 100% of model responses pass it on the way back. Violations are blocked, not flagged after the fact.

Attributed to a person

Every request and every tool call carries the developer's identity and is metered per model. Usage, spend and policy events are answerable: who, which model, how much, when.

Metadata-only records

Policy violations are recorded — what type of violation, by whom, when — never the content that triggered them. Administrators see usage and spend per developer and per model in the portal, and never a transcript.

Tier 2 is a different promise

Frontier OpenAI models are inspected by the gateway rather than by AWS, their output is not inspected, and AWS retains their requests and responses for up to 30 days. Keep anything sensitive on Tier 1, and expect Tier 2 to be described separately wherever it appears.

Simple pricing

A flat monthly fee for the gateway, and prepaid credit for what your developers actually use.

$50 per month, per organization

Covers access to the gateway for your whole team. Your first month's fee is charged one month after you sign up.

$50 starting credit

Charged when you create your organization and added to your account as usage credit straight away. Top up whenever you like.

  • Usage is metered per token, per model, and charged against your credit balance at the rates shown in your portal. Content inspection is included in the price.
  • Prepaid, so spend cannot run away: when the balance runs out, requests stop until you top up.
  • Credit never expires and is not refundable.
  • Cancel any time from Billing. You keep access to the end of the period you have paid for, and your credit stays on your account.
  • Administrators see usage and spend per developer and per model, updated daily.
  • Web search is off unless an administrator turns it on for your organization. When it is on, each search query a tool runs through Aegis is metered and billed per query at the price shown beside the setting, in addition to the model usage that asked for it. A frontier OpenAI model usually runs two or three queries for one search.

Prices in US dollars, exclusive of any applicable taxes. Card payments are taken by our payment processor; card details never reach Aegis.

Search queries are checked against the Aegis content policy by the Aegis gateway before they leave it, and results come from a search index operated by AWS. That check is enforced by the gateway rather than by AWS, so web search carries the frontier models' weaker guarantee whichever model asked for it.

Get started in three steps

From nothing to governed traffic in an afternoon. No AWS account of your own, no server to run.

  1. Create your organization

    Sign in with Google at the portal, name your organization and enter a card. $50 is charged and added as usage credit, and you become the organization's administrator.

    Sign in and create your organization

  2. Invite your developers

    From the portal's Team page, add each developer by their work email. They sign in with the same work identity you did; there is nothing to hand out and nothing to rotate.

  3. Each developer installs Aegis

    The install page has a one-line installer for macOS, Linux and Windows. It does the whole job: installs Aegis, signs the developer in, points their tools at the gateway and sends a real request to prove the path works. Most tools then need nothing more than a new terminal.

What Aegis does not do

Honest limits, so the protection you think you have is the protection you have.

It governs the sanctioned lane only

  • Personal ChatGPT accounts, browser paste and unmanaged tools are outside it. Covering those needs a secure web gateway or endpoint DLP, which Aegis does not provide.
  • The ChatGPT desktop app cannot be pointed at Aegis. Claude Desktop can.

Two tiers, two promises

  • The guarantees on this page that say "enforced by AWS" and "zero data retention" are Tier 1 guarantees. Tier 2 — the frontier OpenAI models — is inspected by the gateway, its output is not inspected, and AWS retains it for up to 30 days.
  • Claude Fable 5 is not offered, deliberately: Amazon Bedrock serves it only with model-provider data sharing enabled, which cannot coexist with the zero data retention that Tier 1 promises. The newest model is the price of that promise.