Aegisify company logo
Aegisify Digital Intelligence – Security Coverage & Evidence Pipeline Health2026-08-20T01:51:49+00:00
Aegisify Digital Intelligence — Coverage & Evidence Health

Know What Aegisify Can See—and Whether the Evidence Is Actually Arriving

Security conclusions are only as trustworthy as the visibility behind them. Aegisify combines sensor coverage and evidence-pipeline health on one page so teams can answer two questions before interpreting a quiet dashboard: Are the right evidence producers available? And is their evidence reaching the tenant ledger with current, continuous delivery?

No evidence is not the same as no threat.Missing, delayed, degraded, disabled, or out-of-scope visibility remains visible instead of becoming a false green state.

Evidence ConfidenceCoverage × Delivery
IdentitySensor health
FilesSensor health
HTTP / APISensor health
WAF / ShieldIntegration health
01ProduceApplication evidence
02QueueDurable delivery
03AcceptTenant ledger
04VerifyFresh + contiguous

The Visibility Question

Can Aegisify See What It Needs to See, and Is the Evidence Actually Arriving?

Coverage and ingestion are different failure domains. A healthy sensor with a broken delivery path is not trustworthy visibility. A healthy pipeline cannot manufacture evidence from a sensor that is disabled or outside scope.

CoverageWhat can be observed?Sensor availability, health, scope, evidence type, latest observation.

×

DeliveryIs evidence arriving?Freshness, sequence continuity, queue backlog, retries, accepted batches, tenant-store availability.

=

ConfidenceHow much can the conclusion support?Healthy, degraded, unavailable, or explicitly out of scope.

Coverage Health

Measure Visibility Sensor by Sensor

Digital Intelligence treats sensor health as a customer-facing visibility contract. Each reported producer contributes only the evidence it actually supports.

Healthy

Reporting normally

The evidence producer is reporting a healthy state. Analysts should still compare the latest observation with pipeline freshness before treating a quiet period as meaningful.

Degraded / Unknown

Confidence must narrow

If a conclusion depends on a degraded or unknown channel, Digital Intelligence keeps that visibility limitation attached to the interpretation.

Not Enabled

Excluded from the conclusion

An optional, disabled, inactive, or unavailable evidence channel does not become “nothing suspicious happened.” It remains a known blind spot.

Out of Scope

No implied coverage

Infrastructure or telemetry outside the implemented application boundary is explicitly identified rather than silently absorbed into a broad security claim.

Coverage Matrix

Application Visibility With Explicit Boundaries

Aegisify Digital Intelligence is designed around supported SaaS application evidence. Coverage expands through connected Aegisify products and enabled sensors, but unsupported infrastructure remains outside the claim.

Application identity & accessHealth-dependent

Supported user, session, authentication, credential, and privilege evidence when the relevant application sensors report it.

Files, integrity & persistenceHealth-dependent

Supported resources, application components, scheduled tasks, integrity, malware, and persistence evidence from enabled Agent or Shield sensors.

Application API / HTTP activityInstrumented paths

Supported application requests, APIs, and egress paths. Custom code that bypasses instrumented hooks can reduce visibility.

WAF / Shield evidenceWhen connected

Inbound enforcement, malware, file-integrity, identity, and related application evidence contributed by the corresponding Aegisify control.

Browser-observable metadataOptional / bounded

Selected script, form, resource-destination, and CSP observations when Browser Trust is enabled. This is not universal browser interception.

Audit evidenceIntegrated context

Audit findings and related evidence can be correlated where synchronized. Scan evidence does not replace runtime evidence health.

Host, appliance & universal network telemetryOutside current scope

Digital Intelligence does not claim packet capture, router/appliance monitoring, universal operating-system telemetry, or broad cloud control-plane coverage through these application sensors.

Evidence Pipeline

Separate a Quiet Application From a Blind Delivery Path

The ingestion view measures whether signed Agent evidence is current, continuous, queued, retried, accepted, and available in the tenant evidence store.

01Agent evidenceSupported application sensors create privacy-reduced event records and health state.
02Durable queuePending evidence, queue size, age, and retry state show delivery pressure instead of hiding it.
03SaaS acceptanceAccepted batches and sequence positions establish what the SaaS control plane has actually acknowledged.
04Tenant evidence ledgerTenant-store availability and accepted writes determine whether the durable evidence can be queried for investigation.

Pipeline States

Health Needs More Than “Connected” or “Disconnected”

Aegisify distinguishes several operational states so a customer can see why confidence is reduced. The exact UI state is derived from current delivery facts, not from whether a page happens to contain zero incidents.

Healthy / currentA recent accepted batch exists and no unresolved sequence gap is reported.
DelayedAccepted evidence exists, but its freshness exceeds the implemented evidence threshold.
BacklogThe Agent reports evidence still waiting for delivery or acknowledgement.
Gap detectedReceived sequence state indicates unresolved evidence between the highest contiguous acknowledgement and later received sequence.
Ingest errorA delivery, repair, database, or tenant-store failure prevents normal confidence.
No batch receivedNo accepted Agent batch is recorded. Evidence is unavailable, not clean.

Freshness & Sequence Continuity

Know Whether the Story Has Missing Pages

A current timestamp alone cannot prove the evidence stream is complete. Digital Intelligence also tracks sequence continuity so later evidence does not hide an unresolved missing range.

ACKed contiguous… 1048Highest sequence known to be continuous
Visibility gap1049–1053Illustrative unresolved range stays visible
Highest received… 1053Later evidence does not erase the gap

When a sequence gap is detected, the system can expose the missing range and keep repair status visible while bounded recovery runs. The key principle is more important than the mechanism: an incomplete stream should never be summarized as a complete quiet period.

Backlog & Delivery Pressure

See Evidence Waiting to Leave the Application

A temporary network or service problem does not have to become invisible. The health contract can report delivery pressure before the SaaS side receives the missing events.

Pending eventsHow many evidence records are waiting for delivery or acknowledgement.
Pending bytesApproximate queued evidence volume in the current health rollup.
Oldest queued ageHow long the oldest pending evidence has remained in the queue.
Retrying eventsHow many queued events have already required another delivery attempt.
Maximum retry attemptShows whether a subset of evidence has been repeatedly difficult to deliver.
Accepted throughputDaily accepted events, batches, and telemetry volume provide operational context without equating volume with risk.

Sensor-Level Evidence

Know What Each Producer Contributes

The coverage view connects product/source, sensor, scope, health, reason, recent evidence types, latest observation, and latest health report instead of reducing visibility to one green status icon.

For supported database-access telemetry, Digital Intelligence also understands a defined Agent-side sensor contract and can distinguish whether a database sensor is enabled from whether that event type happened to fire during the recent evidence window. That matters because enabled with zero recent observations is very different from disabled or unknown.

Database evidence boundary: database query observations are privacy-reduced and pre-execution. An observed statement shape or operation is investigation evidence; it does not by itself prove that a database operation succeeded or returned or changed data.
How to Read a Quiet Dashboard

Ask Three Questions Before You Say “Nothing Happened”

01

Was the relevant sensor enabled and healthy?

If not, the application may simply have been unobserved for the evidence type needed by the conclusion.

02

Was evidence delivery current and continuous?

Delayed batches, backlog, sequence gaps, or tenant-store failures can make a quiet SaaS view incomplete.

03

Is the question inside the application boundary?

Application evidence cannot prove what unsupported host, appliance, endpoint, or network telemetry would have shown.

Coverage & Evidence Health FAQ

Common Questions About Digital Intelligence Visibility

If there are zero events, does that mean the application is clean?

No. Aegisify first needs to know whether relevant sensors are enabled, healthy, and delivering current evidence. An empty stream with missing visibility is explicitly different from an observed quiet period.

What is the difference between sensor health and ingestion health?

Sensor health describes what evidence producers are available and how they are reporting. Ingestion health describes whether their evidence is being delivered, acknowledged, sequenced, and stored successfully. Both matter.

Why does sequence continuity matter if the latest batch is recent?

A recent batch can arrive after an earlier range was missed. Sequence continuity makes that missing range visible so freshness does not hide incompleteness.

Does Digital Intelligence monitor the entire network or operating system?

No. The current customer-facing coverage model is application-focused and can include evidence from connected Aegisify products. Host, appliance, universal network, and broad cloud control-plane telemetry are outside this application-sensor claim unless separately implemented and integrated.

Can a sensor be enabled even if it has no recent events?

Yes. A healthy or enabled sensor can have no matching activity during the selected period. That is why Digital Intelligence keeps health and recent evidence volume as separate facts.

Trust the Visibility Before the Verdict

Make Security Blind Spots Observable.

Aegisify Digital Intelligence keeps coverage, freshness, continuity, backlog, delivery errors, and explicit scope boundaries visible so teams know how much confidence the evidence can support.