Aegisify company logo
Aegisify Shields AI Assistant2026-08-11T23:55:32+00:00

Aegisify Shield — Inventory & AI-Assisted Configs

Scan WordPress Configuration, Build an Encrypted Baseline, Then Use AI With Guardrails

Aegisify Shield separates local configuration scanning, encrypted inventory, and optional AI analysis. Administrators can authorize redacted AI review through Aegisify Core to explain findings or create a reviewable configuration artifact.

AI should advise security decisions, not quietly become the administrator.
Shield keeps collection local by default, redacts approved AI requests, validates recommendations locally, and never applies an AI-generated configuration automatically.
1ScanLocal posture findings
2InventoryEncrypted environment
3ReviewRedacted AI assistance

Configuration Intelligence Workflow

How Shield Moves From Local Evidence to Reviewable Recommendations

Open each stage to see which work stays local, when encrypted records are created, when AI can be contacted, and where administrator approval remains required.

Click a stage to expand

01Scan LocallyNo AI required
Scan Configurations evaluates a broad local WordPress security-control baseline and produces deterministic findings, a scan score, and risk, strength, or review classifications without contacting an AI provider.
02Collect InventoryTechnical environment
Run Inventory collects WordPress, PHP, database, server, plugin, theme, route, role, capability, cron, filesystem, exposure, and Shield context used for security planning.
03Encrypt HistoryBaseline + changes
The first inventory becomes a full baseline. Later runs automatically create incremental comparisons linked to previous records. Inventory payloads and stored AI analysis are encrypted at rest and protected with integrity checks.
04Authorize AIExplicit one-request consent
AI is optional. An administrator must authorize the specific redacted analysis or configuration-generation request before Shield sends approved technical data through Aegisify Core.
05Validate OutputLocal rules remain authority
AI finding IDs and suggested actions are checked against the current local scan. For generated configurations, Shield merges the returned patch locally and validates the complete configuration against its schema and AI-change allowlist.
06Review Before ApplyNo automatic configuration
AI-generated configuration files are stored as reviewable artifacts. They do not change live WordPress settings automatically; activation requires the normal explicit validated configuration-restore workflow.
Local Configuration Scan

Start With Deterministic Security Evidence Before Asking AI

The Configuration Control Center first evaluates the site locally so AI recommendations can be compared with a concrete Shield security baseline.

The local scanner reviews a broad control surface that includes updates, runtime exposure, filesystem and backup artifacts, APIs, identity controls, login and password-reset abuse protection, registration safety, privileged authorization, malware posture, integrity monitoring, logging, security headers, and Shield configuration.

Results are organized into Risk, Strength, and Review findings with severity, evidence, current settings, recommended settings, and explanatory guidance. Supported one-click changes are locally allowlisted, protected by rollback, and followed by a fresh inventory scan.

Important boundary: the scan score is a triage signal, not proof that WordPress is uncompromised or compliant. Review the finding, evidence, and operational impact before changing production controls.
Secure Environment Inventory

Collect the Technical Context Needed for Better Security Decisions

Inventory is separate from AI and does not contact an AI service.

01 — WordPress

Core, Plugins, Themes, Routes, and Roles

Shield inventories WordPress and runtime characteristics, installed software, must-use components, selected route and action information, roles, capabilities, cron events, filesystem context, public exposure indicators, and active Aegisify Shield controls.

02 — Baseline

Full First Run

The first inventory establishes a complete baseline. That baseline gives later records a comparison point for understanding which environment sections changed.

03 — Incremental

Automatic Change Comparison

After a baseline exists, Run Inventory automatically creates incremental comparisons. Each record can reference the prior inventory and track changed sections so configuration drift becomes easier to identify.

04 — Protected Storage

Encrypted Inventory History

Detailed inventory payloads are encrypted at rest in Shield-owned storage and include integrity hashes. The history is bounded to the newest five records, and administrators can download or permanently delete saved inventory when needed.

Privacy Boundary

Inventory Collection Avoids Customer Content and Sensitive Records

The environment inventory is designed around technical posture, not customer-data collection.

The current Shield interface states that local inventory does not collect content bodies, passwords, credentials, sessions, user identities, account numbers, PII, PHI, PCI data, CUI, or raw database records. Security planning usually needs technical structure and control state, not business data.

When AI is later authorized, Shield further redacts the approved request. The AI configuration workflow excludes account/company data, identities, emails, domains, IPs, credentials, PII, PHI, PCI data, CUI, content bodies, raw database rows, paths, endpoints, recipients, and custom source lists.

AI Through Aegisify Core

One AI Connection, Explicit Consent, and Local Validation

Shield does not store the AI provider endpoint or provider API key. AI configuration is managed in Aegisify Core.

Analyze the Current Scan

Explain and Prioritize Findings

After a configuration scan creates an inventory record, an administrator can authorize one redacted AI analysis request. Returned priorities and suggested actions are mapped back to current local finding IDs and the Shield feature catalog before display.

Create a Configuration Artifact

Generate, Merge, and Validate Locally

Select one saved inventory and one saved complete Shield configuration. AI returns a settings patch, not permission to write WordPress. Shield merges that patch locally, validates the complete document, and stores the result as an encrypted-at-rest configuration artifact.

Keep Humans in Control

Review Before Restore

The generated artifact is not applied automatically. Administrators review it and use the same validated restore workflow used for other portable Shield configurations, including rollback protection before live settings are replaced.

AI Safety Boundaries

Some Security Settings Remain Manual by Design

Shield limits AI-generated changes to a local reversible-setting allowlist rather than accepting arbitrary configuration edits.

Controls that can materially affect access, browser behavior, application compatibility, sensitive-data scope, or destructive handling remain outside the AI-change allowlist. The current implementation keeps HSTS, CSP, password policy, REST and XML-RPC restrictions, Data Compliance scope, malware quarantine behavior, master hardening switches, credentials, notification recipients, endpoints, and custom paths under manual administrator review.

Unsupported or schema-invalid AI output does not create a live change. Observations that cannot be deterministically approved remain advisory.

Operating Model

Use the Workflow as a Repeatable Security Review Loop

Use local evidence first, AI assistance second, administrator approval last.

1ScanRun Configuration Scan to establish current findings, score, risks, strengths, review items, and locally safe actions.
2InventoryCollect the encrypted technical baseline and use later incremental records to identify meaningful environmental change.
3AuthorizeUse AI only when additional explanation or configuration assistance is useful, and approve each redacted transmission explicitly.
4VerifyReview generated artifacts, apply only approved changes, then rescan and verify critical workflows.

Evidence Before Automation

Build a WordPress Security Baseline You Can Review and Reuse

Start with local configuration findings and encrypted inventory. Add AI only when its analysis can improve prioritization or help draft a reviewable Shield configuration.

Inventory & AI FAQ

Common Questions About Configuration Intelligence

Does Run Inventory contact an AI provider?

No. Inventory collection is local. AI analysis is a separate action that requires explicit administrator authorization for the redacted request.

Does AI automatically change Shield settings?

No. AI can explain findings or return a supported settings patch. Shield validates the output locally. AI-generated complete configurations are stored as artifacts and require explicit administrator review and the normal validated restore workflow before becoming live.

What is removed before AI configuration generation?

The current workflow excludes identities, emails, account and company data, credentials, PII, PHI, PCI data, CUI, domains, IP addresses, content bodies, raw database rows, endpoints, internal paths, recipients, and other identifying or sensitive configuration values.

How much inventory history does Shield retain?

Encrypted inventory history is bounded to the newest five records, with download and permanent deletion controls.

Aegisify Shield

Turn WordPress Configuration Data Into Controlled Security Decisions

Use local scanning, encrypted inventory, redacted AI analysis, reviewable artifacts, and validated change control without giving AI unchecked authority.