Tenant-scoped row policies
Organization, division, and protection-cell records inherit access through a materialized tenant path and row-level policies.
Phase 1 Prototype / European Protective Intelligence
Aegis now frames the first operating slice: tenant-isolated auth, encrypted VIP records, compliant European OSINT scanning, and a security director dashboard built for action before exposure turns into movement risk.
The Phase 1 backend artifacts in backend/ define the PostgreSQL tenant hierarchy, encryption boundaries, watchlist hash model, and FastAPI route shape needed for implementation.
Organization, division, and protection-cell records inherit access through a materialized tenant path and row-level policies.
VIP names, addresses, documents, and family links stay encrypted at field level with per-tenant data keys.
Watchlist comparisons use deterministic HMAC digests so scans can match sensitive terms without storing raw identifiers.
Passkeys bind security directors to hardware-backed MFA with auditable challenge creation and replay protection.
Recovery is modeled as split authorization: tenant admins can restore access without Aegis reading VIP secrets.
Each module emits normalized findings with source provenance, geospatial confidence, actionability, and legal-basis notes for downstream review.
Opt-in handle monitoring, public mention clustering, travel-routine inference, family-tag risk hints.
Company officer deltas, beneficial ownership signals, director-address spillover, sanctions-adjacent entities.
EXIF residue checks, landmark matching, venue recurrence, residence-proximity scoring.
Exposure severity, adversary actionability, recency, VIP itinerary sensitivity, mitigation state.
Principal, Milan Family Office
Umbra / Private Wealth / Italy DeskPublic Markets CEO, Paris
Umbra / Corporate / France DeskFounder, Madrid
Umbra / Founders / Iberia DeskThree public image posts triangulate within 310m of a Naples coastal property tied to a protected principal.
A new beneficial ownership filing references a hashed associate identifier without exposing the underlying watchlist value.
Removal workflow suppressed two historic school-run references; residual physical-risk confidence decreased by 8 points.
The export action uses print-to-PDF today and is wired for a server-side renderer once the FastAPI report worker is deployed. Print styles preserve executive summary cards, alert context, and portfolio risk scores while hiding navigation chrome.
Clearance-Level Protection
The prototype now presents the product architecture, scanner scope, and director workflow in a single deployable experience.
Join as Founding Member