Saya captures every decision as tamper-evident evidence and tracks every policy block, so an audit is a download, not a fire drill.
Get early accessShe turns governance from paperwork into a by-product of doing the work. When a rule stops an action, Saya shows it in the open and records the exception. When a regulator, client or board asks for proof, the evidence pack is already there.
Saya is in early access, and she’s the reason “every outcome proven” isn’t just a slogan.
Every action signed and recorded end to end, as cryptographically-signed evidence, so an audit becomes a download, not a fire drill.
When a rule stops an action, Saya shows it in the open and tracks the exception. Nothing is quietly swallowed.
Exportable evidence packs whenever a regulator, client or board asks, aligned to ISO 27001 and the NHS DSP Toolkit.
Every action Saya takes is governed and recorded. Here’s what’s true today, and the standards Aegis is working towards across the platform.
Built on AWS infrastructure that is itself ISO 27001, SOC 2 and PCI DSS Level 1 certified, with UK and sovereign deployment options for data residency.
Cyber Essentials Plus · Trade-body supplier accreditation
NHS Data Security & Protection Toolkit (DSPT) · DTAC — Digital Technology Assessment Criteria
ISO/IEC 27001 · SOC 2 (Type 1 → Type 2)
ISO 27017 / ISO 27018 · ISO 22301 (business continuity) · PCI DSS (service provider)
Non-clinical boundary. Aegis operates under a non-clinical intended-use boundary. It handles administrative and operational work: booking, scheduling, reminders, records and routing. It does not provide diagnosis, triage, treatment planning or medical advice; anything clinical is handed to a person.
Aegis is pre-launch. The standards above are what we are actively working towards, not yet awarded. We show status as each is achieved, and we never claim a certification we don’t hold.