Aegisify company logo
Cloud Digital Intelligence GovCloud Integrations2026-09-23T22:39:19+00:00
Pricing + AWS-Native Architecture

Pay Aegisify for Digital Intelligence. Keep AWS Security Capabilities in AWS.

Aegisify DI uses a Protected Workload subscription for the intelligence layer while customers pay AWS directly for the native security capabilities they choose to enable. The result is a transparent commercial model: one DI capacity meter, customer-owned AWS services, and no Aegisify charge for users, AWS accounts, Regions, the Edge connector, or raw-log gigabytes.

Especially important for regulated and government environments: the source security service, AWS partition, Region, assurance scope, customer configuration, data boundary, and evidence path can all matter. Keeping AWS-native evidence inside AWS can simplify architecture—but it does not make Aegisify or a customer system authorized or certified by itself.
1
AWS security spendCustomer enables the native services appropriate to the architecture, threat model, Region, and compliance boundary.
2
DI Protected Workload subscriptionAegisify charges for the intelligence layer and visible protected-estate capacity.
3
Separate, auditable economicsCustomers can see what they pay AWS for security engines and what they pay Aegisify for intelligence.
AWS native foundation → DI intelligence → GovCloud boundary
AWS Native source services remain in AWS
DI Intelligence explain · prioritize · correlate
GovCloud controlled evidence boundary
Security Hub
Inspector
Protected Workloads
Case Workflow
Customer-Owned Evidence
GovCloud Transparency
DI AWS List Pricing

One Protected Workload Capacity Model

$18KStarter — up to 100 PW / year
$36KProfessional — up to 300 PW / year
$54KBusiness — up to 500 PW / year
$90KEnterprise — up to 1,000 PW / year
No DI per-user feeNo DI per-account feeNo DI per-Region feeNo Edge license feeNo DI raw-log GB fee1,001+ custom
Protected Workloads are an Aegisify meter. DI uses a versioned formula across active compute, serverless, application containers, managed runtimes, and normalized image/identity coverage. The customer dashboard uses the same meter for utilization and contract capacity.
Public Market Anchors

Current Public Pricing Shows Different Commercial Models

Vendor / offerPublic pricing anchorWhat scalesImportant note
Aegisify DI$18,000/year for up to 100 PWProtected Workload capacityAWS-native security-service charges are separate.
Wiz Essential$24,000/year for 100 cloud workloadsWorkloadsCurrent AWS Marketplace also lists separate Sensor, Code, and Defend dimensions.
Wiz Advanced$38,000/year for 100 cloud workloadsWorkloadsSensor and Defend are listed as add-ons to Advanced.
Orca Small$7,000/month for up to 100 concurrent EC2 workloadsConcurrent EC2 ceilingCurrent public starter tiers also list 300/$12K, 500/$17K, and 1,000/$30K per month.
Do not treat base-price deltas as guaranteed TCO savings. AWS security services, storage, queries, runtime monitoring, threat analytics, data classification, and other native capabilities may add AWS charges. Competitor negotiated private offers can also differ from public Marketplace prices.
Why AWS-Native Matters

Security Facts Can Stay With the Provider That Owns the Cloud Resource Semantics

Vulnerability

Amazon Inspector

Use AWS-native resource and vulnerability assessment where supported. DI can correlate those findings with exposure, identity, business importance, KEV/EPSS, drift, and evidence.

Threat Detection

Amazon GuardDuty

Use AWS threat detection and runtime signals where supported, then bring findings into DI for cross-signal investigation and response context.

Posture

Security Hub CSPM + AWS Config

Use native resource configuration and control evidence, while DI records relationships, exceptions, coverage, drift, and governance context.

Identity

IAM Access Analyzer

Use AWS policy reasoning for external/internal/unused access, then correlate identity evidence with behavior and attack paths in DI.

Data

Amazon Macie where applicable

Use native sensitive-data discovery for supported S3 use cases. DI can correlate sensitivity with KMS, access, exposure, and criticality. Broader database DSPM is not claimed.

Investigation

CloudTrail, CloudWatch, Detective, Athena

Keep raw or high-volume evidence in customer-controlled AWS sources and retrieve bounded evidence when a case requires it.

Government & Regulated Cloud

AWS-Native Does Not Mean “Automatically Compliant”—It Means the Evidence Path Can Be More Explicit

For government buyers, the important question is not whether a product uses AWS. The important questions are which AWS partition and Region are used, whether the exact service and feature are available and in the required assurance scope, where protected data travels, what the customer must configure, and what evidence supports each control objective.

AWS Assurance Scope

Verify the exact service and program

AWS maintains public services-in-scope pages for programs such as FedRAMP and DoD SRG. The current FedRAMP page distinguishes Class C (formerly Moderate) and Class D (formerly High/GovCloud) scope by service. DI should preserve that distinction instead of assuming every AWS service has the same authorization status.

GovCloud Partition

Commercial and GovCloud are not interchangeable

AWS GovCloud (US) uses separate Regions, ARNs, endpoints, credentials, and feature availability. For example, GuardDuty and Inspector are available in GovCloud, but their documented feature differences must still be checked.

Shared Responsibility

AWS evidence does not eliminate customer responsibility

AWS guidance for CMMC states that security and compliance are shared responsibilities: AWS secures the cloud infrastructure, while customers remain responsible for security in the cloud and for their own required implementation and evidence.

Data Minimization

Keep high-volume evidence in the authorized boundary where possible

DI's default architecture leaves raw AWS telemetry in the customer environment and sends compact resource state, findings, references, hashes, and case evidence to the intelligence layer.

Why this can help government architecture: native AWS services can provide source findings and evidence inside the customer's AWS boundary, and AWS publishes service-specific compliance scope and GovCloud behavior. That can make responsibility and evidence mapping clearer. It does not make DI FedRAMP authorized, CMMC certified, or a customer system compliant.
Current GovCloud Examples

Feature Availability Must Be Verified, Not Assumed

AWS serviceGovCloud status / differenceDI implication
Security HubAWS documents Security Hub in GovCloud and lists supported AWS integrations by GovCloud Region.Use the GovCloud-specific integration set; do not assume commercial parity.
GuardDutyAvailable in GovCloud East/West. AWS documents differences including runtime endpoint/FIPS details and unavailable features.DI must expose coverage by feature and Region rather than simply “GuardDuty enabled.”
Amazon InspectorAvailable in GovCloud East/West, but AWS documents unavailable features such as Lambda Code Scanning and Managed Code Repository Scanning.Code-security coverage in GovCloud must be shown honestly as limited where AWS does not provide the feature.
Amazon DetectiveAvailable in GovCloud East/West with documented differences.Useful as optional investigation context when permitted by the customer architecture.
Pricing & Compliance FAQ

Questions Government and Regulated Buyers Commonly Ask

Does using AWS-native security make DI FedRAMP authorized?

No. AWS service assurance scope, Aegisify's own authorization status, the customer's system boundary, data flows, implementation, and assessor/authorizing-official decisions are separate matters.

Does Security Hub PASSED mean a federal control is satisfied?

No. A native service result can provide technical evidence for a resource configuration or security objective, but the customer still has to map responsibility, inherited controls, implementation, evidence, and assessment requirements.

Why can AWS-native evidence be useful for government buyers?

Because the source service, Region, partition, finding identity, resource ARN, timestamp, and provider evidence can remain attributable to the AWS environment. That can support clearer evidence chains and boundary discussions.

Why are AWS charges separate from the DI subscription?

DI does not hide variable AWS service usage inside the Aegisify price. Customers can see what they pay for AWS security engines and what they pay Aegisify for Digital Intelligence.

Transparent Cloud Security Economics

Use Native AWS Security Where It Fits. Add Digital Intelligence Where It Matters.

Model the AWS services, Protected Workloads, evidence boundary, GovCloud requirements, and total operating cost before deployment.