Pay Aegisify for Digital Intelligence. Keep AWS Security Capabilities in AWS.
Aegisify DI uses a Protected Workload subscription for the intelligence layer while customers pay AWS directly for the native security capabilities they choose to enable. The result is a transparent commercial model: one DI capacity meter, customer-owned AWS services, and no Aegisify charge for users, AWS accounts, Regions, the Edge connector, or raw-log gigabytes.
One Protected Workload Capacity Model
Current Public Pricing Shows Different Commercial Models
| Vendor / offer | Public pricing anchor | What scales | Important note |
|---|---|---|---|
| Aegisify DI | $18,000/year for up to 100 PW | Protected Workload capacity | AWS-native security-service charges are separate. |
| Wiz Essential | $24,000/year for 100 cloud workloads | Workloads | Current AWS Marketplace also lists separate Sensor, Code, and Defend dimensions. |
| Wiz Advanced | $38,000/year for 100 cloud workloads | Workloads | Sensor and Defend are listed as add-ons to Advanced. |
| Orca Small | $7,000/month for up to 100 concurrent EC2 workloads | Concurrent EC2 ceiling | Current public starter tiers also list 300/$12K, 500/$17K, and 1,000/$30K per month. |
Security Facts Can Stay With the Provider That Owns the Cloud Resource Semantics
Amazon Inspector
Use AWS-native resource and vulnerability assessment where supported. DI can correlate those findings with exposure, identity, business importance, KEV/EPSS, drift, and evidence.
Amazon GuardDuty
Use AWS threat detection and runtime signals where supported, then bring findings into DI for cross-signal investigation and response context.
Security Hub CSPM + AWS Config
Use native resource configuration and control evidence, while DI records relationships, exceptions, coverage, drift, and governance context.
IAM Access Analyzer
Use AWS policy reasoning for external/internal/unused access, then correlate identity evidence with behavior and attack paths in DI.
Amazon Macie where applicable
Use native sensitive-data discovery for supported S3 use cases. DI can correlate sensitivity with KMS, access, exposure, and criticality. Broader database DSPM is not claimed.
CloudTrail, CloudWatch, Detective, Athena
Keep raw or high-volume evidence in customer-controlled AWS sources and retrieve bounded evidence when a case requires it.
AWS-Native Does Not Mean “Automatically Compliant”—It Means the Evidence Path Can Be More Explicit
For government buyers, the important question is not whether a product uses AWS. The important questions are which AWS partition and Region are used, whether the exact service and feature are available and in the required assurance scope, where protected data travels, what the customer must configure, and what evidence supports each control objective.
Verify the exact service and program
AWS maintains public services-in-scope pages for programs such as FedRAMP and DoD SRG. The current FedRAMP page distinguishes Class C (formerly Moderate) and Class D (formerly High/GovCloud) scope by service. DI should preserve that distinction instead of assuming every AWS service has the same authorization status.
Commercial and GovCloud are not interchangeable
AWS GovCloud (US) uses separate Regions, ARNs, endpoints, credentials, and feature availability. For example, GuardDuty and Inspector are available in GovCloud, but their documented feature differences must still be checked.
AWS evidence does not eliminate customer responsibility
AWS guidance for CMMC states that security and compliance are shared responsibilities: AWS secures the cloud infrastructure, while customers remain responsible for security in the cloud and for their own required implementation and evidence.
Keep high-volume evidence in the authorized boundary where possible
DI's default architecture leaves raw AWS telemetry in the customer environment and sends compact resource state, findings, references, hashes, and case evidence to the intelligence layer.
Feature Availability Must Be Verified, Not Assumed
| AWS service | GovCloud status / difference | DI implication |
|---|---|---|
| Security Hub | AWS documents Security Hub in GovCloud and lists supported AWS integrations by GovCloud Region. | Use the GovCloud-specific integration set; do not assume commercial parity. |
| GuardDuty | Available in GovCloud East/West. AWS documents differences including runtime endpoint/FIPS details and unavailable features. | DI must expose coverage by feature and Region rather than simply “GuardDuty enabled.” |
| Amazon Inspector | Available in GovCloud East/West, but AWS documents unavailable features such as Lambda Code Scanning and Managed Code Repository Scanning. | Code-security coverage in GovCloud must be shown honestly as limited where AWS does not provide the feature. |
| Amazon Detective | Available in GovCloud East/West with documented differences. | Useful as optional investigation context when permitted by the customer architecture. |
Questions Government and Regulated Buyers Commonly Ask
Does using AWS-native security make DI FedRAMP authorized?
No. AWS service assurance scope, Aegisify's own authorization status, the customer's system boundary, data flows, implementation, and assessor/authorizing-official decisions are separate matters.
Does Security Hub PASSED mean a federal control is satisfied?
No. A native service result can provide technical evidence for a resource configuration or security objective, but the customer still has to map responsibility, inherited controls, implementation, evidence, and assessment requirements.
Why can AWS-native evidence be useful for government buyers?
Because the source service, Region, partition, finding identity, resource ARN, timestamp, and provider evidence can remain attributable to the AWS environment. That can support clearer evidence chains and boundary discussions.
Why are AWS charges separate from the DI subscription?
DI does not hide variable AWS service usage inside the Aegisify price. Customers can see what they pay for AWS security engines and what they pay Aegisify for Digital Intelligence.
How can Aegisify AI help?
Ask about Aegisify or WordPress: errors, plugins, security, SEO, compatibility, troubleshooting, comparisons, or launch a free website scan.
