AEGISGRID
AegisGrid by NetWit

Autonomous Security Agents. Inside Your Perimeter.

AegisGrid turns 20-day HECVAT reviews into 20-minute extractions and SOC alert fatigue into an auditable decision trail. Local inference, signed audit log, no commercial API in the loop.

HECVAT 4.1.6 aligned · NIST AI RMF 1.0 + AI 600-1 GenAI Profile · GLBA Safeguards 16 CFR 314 · NIST CSF 2.0 · NIST 800-171 · Rutgers Policy 70.1.2 compatible · MITRE ATLAS v5.1.0 threat-modeled

01 / Architecture

The AegisGrid Architecture

AegisGrid is built as three composable layers, all of which run on hardware you own, inside the network perimeter you operate. There is no path by which your documents, alerts, or risk matrices reach a third-party inference provider. The architecture diagram below maps directly to the security model on /architecture and the compliance crosswalk on /compliance.

Local Inference Cluster.

Self-hosted LLMs (Llama 3.x, Mistral, Phi-4) running on Ollama or vLLM, with Chroma or Qdrant as the on-prem vector store. No inference request leaves the host. No telemetry leaves the host. This is the layer that makes "no data egress" a physical claim rather than a policy claim.

Agent Orchestrator.

A multi-agent runtime (LangGraph or CrewAI) that sequences Intake → Extract → Map → Score agents, each with explicit tool scopes and a hash-chained append-only audit log of every tool call, prompt, and decision. Every action is replayable. Every action is signed.

Integration Layer.

Bidirectional connectors into the systems you already run — ServiceNow for ticket workflow, Splunk / Sentinel / Elastic for alert streams, email for vendor document intake. The integration layer talks to your systems; the inference layer talks to no one.

Data flow stays inside the perimeter
AegisGrid agentic runtime architectureServiceNow, SIEM, and vendor documents enter a local multi-agent runtime. The runtime uses local inference and vector storage, writes to an append-only audit log, and returns decisions to human analysts. A CISO retains a millisecond kill switch.RUTGERS PERIMETER · YOUR HARDWARE, YOUR DATAINPUTSSERVICENOW / SIEM / EMAILServiceNow TicketSIEM Alert StreamVendor PDF / HECVATAEGISGRID AGENTIC RUNTIMEEXPLICIT SCOPES · REPLAYABLE ACTIONSIntake Agent · document parsingExtract Agent · schema-bound LLMMap AgentScore Agent · risk matrixAppend-Only Audit Loghash-chained · signed · replayableLOCAL INFERENCE CLUSTERNO DATA EGRESSOllama RuntimeLlama 3.x / Mistral / Phi-4Vector StoreChroma / Qdrant · self-hostedHUMAN IN COMMANDSecurity Analyst · final go/no-goCISO / Director · containment switchmillisecond kill switchwork notes / queue update

02 / Operating reality

The Higher-Ed Problem, Quantified

Three numbers, three sources, three reasons the current operating model is breaking.

TPRM cycle time

7–20

business days

Source: Rutgers ISO, "Information Security Risk Management — Frequently Asked Questions," it.rutgers.edu/cybersecurity-risk-management-program/information-security-risk-management-frequently-asked-questions-faq/

HECVAT scope

332

questions · 35 categories · 32-question AI subsection

Source: Counted directly from the EDUCAUSE HECVAT 4.1.6 workbook Questions sheet on 2026-07-24. 332 question records across 35 categories and 8 evaluation tabs. AI subsection: 32 questions (AIQU=2, AIGN=5, AIPL=5, AISC=5, AIML=8, AILM=7) plus the REQU-04 gate question that activates it. The EDUCAUSE marketing page references 321 / 7 sections; the actual workbook contains 332 / 8 tabs / 35 categories.

SOC alert reduction

~70–80%

target reduction

Source: Industry analyst consensus in 2025–2026. A specific Gartner report reference could not be verified at draft time; language is intentionally non-specific.

03 / First deployments

Two Wedge Use Cases

Two places we earn the right to talk to you again.

HECVAT wedge

A vendor security review under HECVAT 4.1.6 is 332 questions across 35 categories and 8 evaluation tabs, plus a conditional 32-question AI subsection that aligns to NIST AI RMF AIPL-05. The average Rutgers analyst has no institutional muscle memory for the AI subsection yet. AegisGrid ingests the SOC 2 or HECVAT vendor artifact, extracts control statements against the published schema, maps each to the relevant Rutgers policy clause (Policy 70.1.2 classification, GLBA Safeguards controls), and produces a draft risk matrix in the High / Medium-High / Medium-Low / Low taxonomy Rutgers uses. The analyst reviews, edits, and signs off. Deep dive on /hecvat-automation.

Read the deep dive

SOC wedge

The Rutgers Security Operations Center manages 100+ firewalls and the alert stream that comes with them. Industry analyst consensus in 2025–2026 puts the modern SOC alert-reduction target at 70–80%. AegisGrid ingests SIEM alerts, enriches them with on-prem threat intel and asset context, and routes them through an auditable reasoning chain — either escalating to a ServiceNow analyst queue with full lineage or auto-closing with a hash-chained audit entry when confidence is high and risk is low. Deep dive on /soc-triage.

Read the deep dive

04 / Framework posture

Compliance, Not Marketing

Every framework below is one AegisGrid was designed against. None are certifications AegisGrid currently holds — we use "aligned with" / "designed for" / "maps to" language deliberately, because a CISSP will read the difference.

What we will not do.

  • We will not train on your data.
  • We will not transmit your data to commercial APIs.
  • We will provide an immutable, hash-chained audit log of every agent action.
  • We will keep a human in command of every containment decision.

05 / Who builds this

Built by CISSPs, For CISOs

Founder / NetWit

Dave Chatpar

ISC² member · 18 years of enterprise security experience

AegisGrid is built by Dave Chatpar — an ISC² member with 18 years of enterprise security experience across Zero Trust architecture, cloud security posture management (CSPM), and micro-segmentation. Dave founded NetWit, the parent company behind AegisGrid, PostMTA, and CanFlows.ca. He is based in Vancouver and works directly with every evaluation customer.

AegisGrid is the agentic-orchestration layer we wished existed when we ran security programs ourselves. The product is engineered for the audience that has been burned by "autonomous" tools that turned out to mean "untraceable" — every agent action is logged, every decision is replayable, and the containment switch is a millisecond-time primitive, not a feature request.

Note on credentials: Dave holds the CISSP. Other certifications are not asserted here. Where additional credentials exist, they are documented in the internal pre-call dossier for sales use only.

More about NetWit

Autonomous Security Agents. Inside Your Perimeter.

AegisGrid turns 20-day HECVAT reviews into 20-minute extractions and SOC alert fatigue into an auditable decision trail. Local inference, signed audit log, no commercial API in the loop.