About AegisBreach

Security posture clarity with honest boundaries

AegisBreach is a B2B cybersecurity SaaS that helps teams understand website security posture through passive configuration evidence, structured reporting, and clear remediation guidance—without fear-based claims or fabricated trust signals.

  • Passive-first by design
  • Evidence-led reporting
  • Scope transparency

What we do

B2B cybersecurity SaaS for website posture

AegisBreach reviews publicly visible configuration signals—TLS, HTTP headers, DNS, and email security records—and organizes findings into an Aegis Score with actionable guidance for business and technical audiences.

Our approach

Posture evidence, not fear marketing

We focus on what can be observed safely from public configuration and documented scan boundaries. Reports connect impact, technical context, and remediation steps so owners and developers can act on the same evidence.

Who it serves

Teams that need clarity before deeper work

Business websites, agencies supporting verified client domains, and e-commerce operators who need bounded surface review with explicit authorization gates—not a substitute for a full red-team engagement or compliance certification.

What we are not

AegisBreach does not claim guaranteed security, zero risk, external audits, penetration-test certification, or production-ready operational status. We do not present customer counts, partner logos, or fabricated social proof.

Product family

Current packages

The product progresses from a free passive preview to verified-domain paid reporting. Agency Shield and Enterprise Shield are future packages and are not implemented.

Free Scan

Free Scan

Anonymous passive preview for any public domain. No account or domain ownership required.

What you get

  • Passive public-configuration checks
  • Aegis Score preview
  • Safe scope only—no deep or intrusive testing
  • Free in all markets

Starter Shield

Starter Shield

Recommended

Verified-domain passive posture reporting for business websites. Local/test MVP complete; not production-ready.

What you get

  • Verified domain required before paid scanning
  • Full findings with remediation guidance
  • Scan history and functional PDF export locally/test
  • Passive website posture—no active pentesting

E-commerce Shield Pro

E-commerce Shield Pro

Pro Verified Audit for e-commerce with verified domain and explicit scan scope confirmation. Local/test MVP complete; Phase 7 active checks remain deferred.

What you get

  • Everything in Starter Shield baseline
  • Explicit scan scope confirmation required
  • E-commerce passive modules within approved scope
  • Not a substitute for compliance certification

Trust and safety

Clear boundaries from preview to paid scanning

Checks stay within documented safe and passive boundaries unless explicit client-approved scope authorizes more—and paid scanning always requires verified domain ownership.

SAFE BY DESIGN

Security testing with clear boundaries

AegisBreach keeps checks controlled from target authorization through evidence-led reporting.

  • Passive-first checks

    Low-risk signals lead before deeper authorized testing.

  • Verified paid targets

    Paid scans require verified-domain ownership.

  • Explicit scope controls

    Checks stay within the approved target and package.

  • Evidence-led reporting

    Findings connect impact, technical context, and next steps.

Safe checks

What automated scanning covers today

  • Public DNS, HTTPS/TLS, HTTP security headers, and email security signals where available from public records
  • Passive configuration evidence without payload execution or uncontrolled active probes on Free Scan and Starter Shield
  • E-commerce Shield Pro surface checks within documented module boundaries and approved scope

Authorization gates

Where we stop without explicit approval

  • Paid scanning requires a verified domain and an active entitlement
  • E-commerce Shield Pro requires explicit scan scope confirmation before active or application-layer checks would run
  • No checkout, payment capture, credential stuffing, or intrusive testing in the current automated scope

Current status

Honest product and availability truth

We publish what exists today—not what is planned, certified, or implied by staging work alone.

Local and test MVPs

Starter Shield and E-commerce Shield Pro local/test MVP functionality exists and has been validated in development environments.

Staging validation

Controlled staging validation has been performed for parts of the public experience. Staging validation does not authorize or imply production rollout.

Not production-ready

The product is not production-ready SaaS today. Production is not provisioned or deployed. Launch gates and operational hardening remain open.

Billing and checkout

Initial launch billing is a one-time card purchase. Each paid purchase grants 31 days of access with fixed package scan and domain limits. There is no automatic renewal. A payment provider is not selected and live card checkout is not enabled.

What remains deferred

  • Agency Shield and Enterprise Shield are future packages—not implemented and not purchasable
  • Admin Panel is required for operational control but is not implemented; manual CLI activation remains the secondary operational path
  • Premium UI polish, production deployment hardening, and full production QA remain open workstreams

Next step

Start with evidence you can verify

Run a free passive posture preview or review current package pricing and limits. No payment details are collected on either path today.

  • Free Scan requires no account
  • Paid packages require verified domain ownership
  • Live card checkout is not enabled

Results depend on the target, package, authorization, and publicly available evidence.