Autonomous Security Agents. Inside Your Perimeter.
AegisGrid turns 20-day HECVAT reviews into 20-minute extractions and SOC alert fatigue into an auditable decision trail. Local inference, signed audit log, no commercial API in the loop.
AegisGrid is built as three composable layers, all of which run on hardware you own, inside the network perimeter you operate. There is no path by which your documents, alerts, or risk matrices reach a third-party inference provider. The architecture diagram below maps directly to the security model on /architecture and the compliance crosswalk on /compliance.
Local Inference Cluster.
Self-hosted LLMs (Llama 3.x, Mistral, Phi-4) running on Ollama or vLLM, with Chroma or Qdrant as the on-prem vector store. No inference request leaves the host. No telemetry leaves the host. This is the layer that makes "no data egress" a physical claim rather than a policy claim.
Agent Orchestrator.
A multi-agent runtime (LangGraph or CrewAI) that sequences Intake → Extract → Map → Score agents, each with explicit tool scopes and a hash-chained append-only audit log of every tool call, prompt, and decision. Every action is replayable. Every action is signed.
Integration Layer.
Bidirectional connectors into the systems you already run — ServiceNow for ticket workflow, Splunk / Sentinel / Elastic for alert streams, email for vendor document intake. The integration layer talks to your systems; the inference layer talks to no one.
Data flow stays inside the perimeter
02 / Operating reality
The Higher-Ed Problem, Quantified
Three numbers, three sources, three reasons the current operating model is breaking.
questions · 35 categories · 32-question AI subsection
Source: Counted directly from the EDUCAUSE HECVAT 4.1.6 workbook Questions sheet on 2026-07-24. 332 question records across 35 categories and 8 evaluation tabs. AI subsection: 32 questions (AIQU=2, AIGN=5, AIPL=5, AISC=5, AIML=8, AILM=7) plus the REQU-04 gate question that activates it. The EDUCAUSE marketing page references 321 / 7 sections; the actual workbook contains 332 / 8 tabs / 35 categories.
SOC alert reduction
~70–80%
target reduction
Source: Industry analyst consensus in 2025–2026. A specific Gartner report reference could not be verified at draft time; language is intentionally non-specific.
03 / First deployments
Two Wedge Use Cases
Two places we earn the right to talk to you again.
HECVAT wedge
A vendor security review under HECVAT 4.1.6 is 332 questions across 35 categories and 8 evaluation tabs, plus a conditional 32-question AI subsection that aligns to NIST AI RMF AIPL-05. The average Rutgers analyst has no institutional muscle memory for the AI subsection yet. AegisGrid ingests the SOC 2 or HECVAT vendor artifact, extracts control statements against the published schema, maps each to the relevant Rutgers policy clause (Policy 70.1.2 classification, GLBA Safeguards controls), and produces a draft risk matrix in the High / Medium-High / Medium-Low / Low taxonomy Rutgers uses. The analyst reviews, edits, and signs off. Deep dive on /hecvat-automation.
The Rutgers Security Operations Center manages 100+ firewalls and the alert stream that comes with them. Industry analyst consensus in 2025–2026 puts the modern SOC alert-reduction target at 70–80%. AegisGrid ingests SIEM alerts, enriches them with on-prem threat intel and asset context, and routes them through an auditable reasoning chain — either escalating to a ServiceNow analyst queue with full lineage or auto-closing with a hash-chained audit entry when confidence is high and risk is low. Deep dive on /soc-triage.
Every framework below is one AegisGrid was designed against. None are certifications AegisGrid currently holds — we use "aligned with" / "designed for" / "maps to" language deliberately, because a CISSP will read the difference.
We will not transmit your data to commercial APIs.
We will provide an immutable, hash-chained audit log of every agent action.
We will keep a human in command of every containment decision.
05 / Who builds this
Built by CISSPs, For CISOs
Founder / NetWit
Dave Chatpar
ISC² member · 18 years of enterprise security experience
AegisGrid is built by Dave Chatpar — an ISC² member with 18 years of enterprise security experience across Zero Trust architecture, cloud security posture management (CSPM), and micro-segmentation. Dave founded NetWit, the parent company behind AegisGrid, PostMTA, and CanFlows.ca. He is based in Vancouver and works directly with every evaluation customer.
AegisGrid is the agentic-orchestration layer we wished existed when we ran security programs ourselves. The product is engineered for the audience that has been burned by "autonomous" tools that turned out to mean "untraceable" — every agent action is logged, every decision is replayable, and the containment switch is a millisecond-time primitive, not a feature request.
Note on credentials: Dave holds the CISSP. Other certifications are not asserted here. Where additional credentials exist, they are documented in the internal pre-call dossier for sales use only.
Autonomous Security Agents. Inside Your Perimeter.
AegisGrid turns 20-day HECVAT reviews into 20-minute extractions and SOC alert fatigue into an auditable decision trail. Local inference, signed audit log, no commercial API in the loop.