Endpoint · Aegis Agent

One agent, not a zoo

Patching, AI governance and DLP from a single, tamper-resistant cross-platform agent.

The problem

Every security capability wants its own endpoint agent. You end up with five agents fighting for resources — and trust.

What Shadow Span does

Aegis is a single Go agent for Linux, macOS and Windows that does software inventory, signed automated patching, AI-tool/MCP discovery and DLP — with ed25519-signed commands, a TLS pin manifest and signed auto-update.

Endpoint · Aegis Agent in Shadow Span

One agent across the fleet — Linux, macOS and Windows

What you get

One agent, many jobs

Inventory, patch, AI discovery and DLP in a single binary.

Signed control

ed25519 per-command signing — a compromised server cannot dispatch arbitrary patches.

Pinned TLS trust

Chain-pinned manifest with an offline trust anchor for zero-touch cert rotation.

Safe auto-update

Signature-verified updates with healthcheck rollback.

Burst-mode dispatch

Scales toward ~600k endpoints without pinning a connection per device.

Privacy-first

Consent-gated DLP, on-device scanning and pseudonymization.

How it works

01

Enroll

Each agent generates an ed25519 keypair at enrollment.

02

Heartbeat

Lightweight heartbeat carries policy and a command-wakeup hint.

03

Signed jobs

Patch and DLP jobs are verified on-device before execution.

04

Verify + report

Outcomes verified post-action and reported back.

Why Shadow Span

The one agent that powers vuln patching, AI governance and DLP at once — so you deploy a single trusted binary, not a fleet of them.

ReplacesAutomoxseparate EDR / DLP agents

One platform. Not ten point tools.

See Endpoint · Aegis Agent alongside the rest of your security program — correlated, not siloed.