We store governance metadata, not your prompts.

Aegistra only needs to know what a system is and who looks after it.

No model traffic
Aegistra is not in the path between your apps and AI providers. It records what a system is, who owns it and when it was reviewed. It never sees your prompts, outputs or the data you send to models.
Isolated workspaces
Every record belongs to one workspace. Access is enforced by row-level security in the Postgres database, not only by what the screens show.
Keys stay on the server
Your browser only receives a publishable key. The secret key used by the admin area never leaves the server.
Hosted on trusted infrastructure
Aegistra is served over HTTPS from Vercel. Sign-in and data are handled by Supabase.