Case Study / AI Security & Governance

Give 1,000 employees AI access. Keep control.

Aegis gives the enterprise one governed path to approved OpenAI and Anthropic models through AWS. Hatchery is working directly with the Amazon Bedrock team to protect identity, company data, access, and usage at organizational scale, without storing or logging prompt and response content.

Aegis case-study illustration showing developer identity, governed AI access, content policy, Amazon Bedrock models, and usage visibility.
1,000 people One governed access model Manage employees, approved models, permissions, revocation, and policy from an organizational boundary instead of trusting 1,000 separate decisions.
AWS Direct Bedrock collaboration Hatchery is working directly with the Amazon Bedrock team to make the architecture practical, secure, and production-ready.
Zero prompts Stored or logged by Aegis Aegis does not retain or log prompt, response, or tool-output content.
OpenAI + Anthropic Approved models, one boundary Teams use powerful models through governed AWS access instead of unmanaged personal accounts and scattered provider keys.
At a glance

Aegis

Every unmanaged AI account is another place your source code, customer data, and company knowledge can leave your control.

Hatchery built Aegis first because its own engineers could not safely place source code, product plans, customer context, and company knowledge into unmanaged AI accounts.
Aegis gives organizations one place to manage who can use AI, which models are approved, what policy applies, and how access is revoked.
Approved model access runs through a governed AWS architecture designed for enterprise identity, policy, visibility, and multi-AZ operation.
Aegis does not store or log prompts, responses, or tool output. Administrators retain identity, model, token, spend, and policy-event visibility without building a transcript warehouse.
Problem

Your employees are already using AI. Do you know where company data is going?

At enterprise scale, personal accounts, copied keys, public model interfaces, and tool-specific settings become an unmanaged access network. Security teams cannot reliably answer who is using which model, what data boundary applies, how access is revoked, or whether sensitive work is leaving approved systems.

Risk

A single prompt can carry the value of the business outside it.

Source code, trade secrets, designs, customer information, contracts, strategy, and operating context can all appear in a prompt. One careless paste or unmanaged credential can create legal, security, ownership, and regulatory exposure before leadership knows it happened.

Hatchery role

Give people a safer path that is easier than going around it.

Aegis sits between familiar AI tools and approved models accessed through AWS. It binds every request to organizational identity, applies policy, controls model access, meters usage, and supports rapid revocation. Hatchery is working directly with the Amazon Bedrock team to turn that architecture into a production service people will actually use.

Comparison

Many separate AI decisions. One enterprise boundary.

Need Direct or unmanaged access Aegis
Identity Personal accounts and static keys can outlive the employee, project, or device that received them. Short-lived access is tied to organizational identity, making onboarding and revocation controlled operations.
Employee workflow Governance often means replacing preferred tools or asking people to follow a separate manual process. Claude Code, Codex CLI, Claude Desktop, and OpenAI-compatible clients can use one governed access path.
Policy Sensitive-content rules depend on individual judgment or settings scattered across tools. Requests follow managed policy with explicit enforcement and documented model-path boundaries.
Data boundary Retention and provider behavior vary by account, product, and model path. Content and operational metadata are deliberately separated, with model-path disclosures stated clearly for administrators.
Visibility Usage, spend, and policy events are difficult to attribute across keys and services. Identity, model, tokens, spend, timing, and policy events remain visible without retaining a transcript of employee work.
Scale Every new employee, team, model, and tool adds another credential and another place policy can drift. Access, approved models, revocation, policy, usage, and spend can be managed as one organizational system.
What Hatchery built

Built as one product system.

Strategy, design, code, integrations, infrastructure, and operations move together so the product can launch and keep serving customers.

Identity-first access

Developers sign in with organizational identity and receive short-lived access maintained by a local helper. There is no static model API key to copy, commit, or rotate.

Approved OpenAI and Anthropic model access

Aegis connects familiar tools to approved model paths through AWS so teams can use the intelligence they need without turning every provider account into a separate security boundary.

Governed model paths

Amazon Bedrock model access is organized into clearly described tiers so content inspection, enforcement location, output inspection, and retention expectations remain explicit.

Content-minimizing operational visibility

Identity, model, token, spend, timing, and policy-event metadata support administration without turning employee AI work into a searchable transcript warehouse.

Operational resilience

The service uses multi-AZ AWS architecture, monitored access paths, and model-routing options designed to reduce ordinary infrastructure and provider disruption without promising that outside models can never fail.

Enterprise administration at human scale

Whether the organization has 10 people or 1,000, administrators receive one place to manage access, approved models, revocation, usage, spend, and policy events without reading employee prompts.

Decisions

Product choices that made the work hold together.

01

Protect Hatchery before selling the idea

Aegis began with a real internal requirement: our engineers needed AI tools, but Hatchery could not accept unmanaged access to code, product plans, customer context, or company knowledge.

02

Remove static model keys from daily work

Identity and short-lived access make onboarding, revocation, attribution, and auditability more reliable than distributing long-lived provider credentials.

03

State different guarantees plainly

Model tiers do not share identical enforcement or retention behavior. Aegis documents those differences so administrators and developers can make an informed choice.

04

Observe behavior without retaining content

Security teams need evidence of access, model use, spend, and policy events, not a warehouse of proprietary prompts. Aegis keeps operational metadata and excludes prompt, response, and tool-output content.

Aegis today

Aegis is available for organizations that need employees to use AI without creating an unmanaged data-exposure problem. It combines organizational identity, approved model paths through AWS, policy, revocation, usage and spend visibility, and multi-AZ operations in one enterprise access layer.

What this demonstrates

Aegis demonstrates what Hatchery brings beyond code: direct AWS collaboration, enterprise security thinking, product design, model integration, identity, administration, DevSecOps, and the discipline to make a safer path easier for employees to adopt.

Models are becoming commodities, but we should be able to use them without worrying about the privacy and ownership of what we build. That is why Hatchery developed Aegis.
Cody Remer Principal Software Engineer
Security architecture

Governed access without a prompt warehouse.

Aegis keeps AI content moving through approved model paths while identity, policy, usage, and spend remain visible to the organization.

One controlled path from employee to model.
Access boundary

One controlled path from employee to model.

Organizational identity, short-lived access, policy, and approved model routes replace scattered personal accounts and static provider keys.

See AI use without storing the work.
Operational visibility

See AI use without storing the work.

Administrators can see identity, model, tokens, spend, timing, and policy events while Aegis excludes prompt, response, and tool-output content.

FAQ

Common questions.

Why did Hatchery build Aegis?

Hatchery built Aegis first for its own safety. Our engineers needed OpenAI and Anthropic models without sending source code, product plans, customer context, and company knowledge through unmanaged accounts or static provider keys.

Does Aegis retain prompts or responses?

No. Aegis does not store or log prompt, response, or tool-output content. It records operational metadata such as user, model, tokens, spend, timing, and policy events so the organization can manage AI use without retaining employee transcripts.

Which tools can use Aegis?

Aegis supports Claude Code, Codex CLI, Claude Desktop, and OpenAI-compatible clients and SDKs. Product support can evolve, so the Aegis marketing site remains the current compatibility source.

Can Aegis manage AI access across a large organization?

Yes. Aegis is designed to centralize organizational identity, user access, approved models, revocation, policy, usage, and spend whether AI is used by a small technical group or 1,000 employees.

Is Hatchery working directly with AWS?

Yes. Hatchery is working directly with the Amazon Bedrock team to make Aegis practical, secure, and production-ready while providing governed access to approved OpenAI and Anthropic models through the AWS architecture.

Can Aegis prevent every AI outage?

No outside model service is infallible. Aegis uses multi-AZ AWS architecture, monitoring, approved routing, and inference-profile support where available to reduce common infrastructure and provider disruption and make failures easier to see and manage.

Where can an organization learn more or create an account?

Current product details, security disclosures, supported tools and models, and account access are available at hatchery-aegis.com.

Build with Hatchery

Take the product idea, complex workflow, or AI opportunity and make it real.

Clarify what to build, what to simplify, what to protect, and what must work first.

Idea UX Code AI + data Launch Operate Evolve

Start with Hatchery when

Clarify the path

Talk through the build