Aegisify Shield — Inventory & AI-Assisted Configs
Scan WordPress Configuration, Build an Encrypted Baseline, Then Use AI With Guardrails
Aegisify Shield separates local configuration scanning, encrypted inventory, and optional AI analysis. Administrators can authorize redacted AI review through Aegisify Core to explain findings or create a reviewable configuration artifact.
Shield keeps collection local by default, redacts approved AI requests, validates recommendations locally, and never applies an AI-generated configuration automatically.
Configuration Intelligence Workflow
How Shield Moves From Local Evidence to Reviewable Recommendations
Open each stage to see which work stays local, when encrypted records are created, when AI can be contacted, and where administrator approval remains required.
Click a stage to expand
01Scan LocallyNo AI required
02Collect InventoryTechnical environment
03Encrypt HistoryBaseline + changes
04Authorize AIExplicit one-request consent
05Validate OutputLocal rules remain authority
06Review Before ApplyNo automatic configuration
Start With Deterministic Security Evidence Before Asking AI
The Configuration Control Center first evaluates the site locally so AI recommendations can be compared with a concrete Shield security baseline.
The local scanner reviews a broad control surface that includes updates, runtime exposure, filesystem and backup artifacts, APIs, identity controls, login and password-reset abuse protection, registration safety, privileged authorization, malware posture, integrity monitoring, logging, security headers, and Shield configuration.
Results are organized into Risk, Strength, and Review findings with severity, evidence, current settings, recommended settings, and explanatory guidance. Supported one-click changes are locally allowlisted, protected by rollback, and followed by a fresh inventory scan.
Collect the Technical Context Needed for Better Security Decisions
Inventory is separate from AI and does not contact an AI service.
Core, Plugins, Themes, Routes, and Roles
Shield inventories WordPress and runtime characteristics, installed software, must-use components, selected route and action information, roles, capabilities, cron events, filesystem context, public exposure indicators, and active Aegisify Shield controls.
Full First Run
The first inventory establishes a complete baseline. That baseline gives later records a comparison point for understanding which environment sections changed.
Automatic Change Comparison
After a baseline exists, Run Inventory automatically creates incremental comparisons. Each record can reference the prior inventory and track changed sections so configuration drift becomes easier to identify.
Encrypted Inventory History
Detailed inventory payloads are encrypted at rest in Shield-owned storage and include integrity hashes. The history is bounded to the newest five records, and administrators can download or permanently delete saved inventory when needed.
Inventory Collection Avoids Customer Content and Sensitive Records
The environment inventory is designed around technical posture, not customer-data collection.
The current Shield interface states that local inventory does not collect content bodies, passwords, credentials, sessions, user identities, account numbers, PII, PHI, PCI data, CUI, or raw database records. Security planning usually needs technical structure and control state, not business data.
When AI is later authorized, Shield further redacts the approved request. The AI configuration workflow excludes account/company data, identities, emails, domains, IPs, credentials, PII, PHI, PCI data, CUI, content bodies, raw database rows, paths, endpoints, recipients, and custom source lists.
One AI Connection, Explicit Consent, and Local Validation
Shield does not store the AI provider endpoint or provider API key. AI configuration is managed in Aegisify Core.
Explain and Prioritize Findings
After a configuration scan creates an inventory record, an administrator can authorize one redacted AI analysis request. Returned priorities and suggested actions are mapped back to current local finding IDs and the Shield feature catalog before display.
Generate, Merge, and Validate Locally
Select one saved inventory and one saved complete Shield configuration. AI returns a settings patch, not permission to write WordPress. Shield merges that patch locally, validates the complete document, and stores the result as an encrypted-at-rest configuration artifact.
Review Before Restore
The generated artifact is not applied automatically. Administrators review it and use the same validated restore workflow used for other portable Shield configurations, including rollback protection before live settings are replaced.
Some Security Settings Remain Manual by Design
Shield limits AI-generated changes to a local reversible-setting allowlist rather than accepting arbitrary configuration edits.
Controls that can materially affect access, browser behavior, application compatibility, sensitive-data scope, or destructive handling remain outside the AI-change allowlist. The current implementation keeps HSTS, CSP, password policy, REST and XML-RPC restrictions, Data Compliance scope, malware quarantine behavior, master hardening switches, credentials, notification recipients, endpoints, and custom paths under manual administrator review.
Unsupported or schema-invalid AI output does not create a live change. Observations that cannot be deterministically approved remain advisory.
Use the Workflow as a Repeatable Security Review Loop
Use local evidence first, AI assistance second, administrator approval last.
Evidence Before Automation
Build a WordPress Security Baseline You Can Review and Reuse
Start with local configuration findings and encrypted inventory. Add AI only when its analysis can improve prioritization or help draft a reviewable Shield configuration.
Common Questions About Configuration Intelligence
Does Run Inventory contact an AI provider?
No. Inventory collection is local. AI analysis is a separate action that requires explicit administrator authorization for the redacted request.
Does AI automatically change Shield settings?
No. AI can explain findings or return a supported settings patch. Shield validates the output locally. AI-generated complete configurations are stored as artifacts and require explicit administrator review and the normal validated restore workflow before becoming live.
What is removed before AI configuration generation?
The current workflow excludes identities, emails, account and company data, credentials, PII, PHI, PCI data, CUI, domains, IP addresses, content bodies, raw database rows, endpoints, internal paths, recipients, and other identifying or sensitive configuration values.
How much inventory history does Shield retain?
Encrypted inventory history is bounded to the newest five records, with download and permanent deletion controls.
How can Aegisify AI help?
Ask about Aegisify products, WordPress security, support, comparisons, or launch a free website scan.
