AEGIS BY PYPER3

Know when training is heading toward failure.

AEGIS is built to detect emerging training instability from internal training dynamics.

Run the detection-only Trial inside your own environment. No training data leaves your infrastructure. No intervention capability.

View the Evidence Read the Docs →
Illustrative training-run timeline
Not a specific validated run
Training steps →
AEGIS internal signal
Existing loss monitoring
Warning window
Estimate Your Exposure
Your numbers, not ours. Edit these to match your environment.
Estimated monthly cost of failed or degraded runs
$0
This is your own exposure, based on your inputs above. How much of it is detectable before the damage compounds is what the AEGIS Trial measures on your workload, not a percentage we apply for you.
1,308
Training runs, historical dataset
4 model families · earlier implementation
5/5
Fresh-seed detection passes
Prospective validation · current detector
USPTO
U.S. provisional, filed May 2026
Plus CIPO application, filed Aug 2026
02
Risk Reversal

Don't trust our claims.
Test them.

Run AEGIS Trial against your own training workloads. It observes training dynamics and reports detected events for your review. It cannot change your training run, full stop.

The job here is simple: installing AEGIS should feel like trying a developer tool, not signing off on an institutional decision.

01 · Local
Runs inside your infrastructure.
AEGIS Trial executes locally. It does not phone home with your weights, activations, gradients, or training data.
02 · Passive
Detection-only. No intervention.
The Trial artifact contains no intervention capability. It cannot touch gradients, optimizer state, checkpoints, or execution.
03 · No obligation
Run it. Keep it, or remove it.
A bounded evaluation on your own workload. If the signal is useful, we talk. If it isn't, uninstall it.
03
Integration

Integrate in minutes, not days.

The docs are built for engineers and for agentic coding tools. Hand AEGIS's documentation and your existing training loop to Claude Code, Codex, Cursor, or another coding agent, and the basic hooks go in fast.

AegisMonitor · aegis-trial-sdk
# install
pip install aegis-trial-sdk
# live detection also needs a compatible aegis-trial-core wheel,
# supplied separately after Trial approval

# integrate
from aegis import AegisMonitor

monitor = AegisMonitor(model=model)

for step in range(1, total_steps + 1):
    monitor.begin_step(step)
    ...
    loss.backward()
    optimizer.step()
    event = monitor.end_step(loss=loss)
    # event.detected, event.anomaly_state, event.detection_confidence

This mirrors the public demo's actual training loop. A dependency-free preview mode is also available, it simulates telemetry without loading a model or Trial Core.

View the source on GitHub → Request Trial access for the core wheel and full quickstart →
04
What the Trial Does

Observe without giving up control.

This isn't just documentation. It's the core of what the Trial promises.

AEGIS Trial can
  • Observe approved training telemetry
  • Detect AEGIS events
  • Report event severity
  • Surface event timing
  • Surface detections for operator review
  • Generate an evaluation report
AEGIS Trial cannot
  • Change gradients
  • Modify optimizer state
  • Alter checkpoints
  • Change learning rate
  • Stop or restart training
  • Automatically intervene
View Security Architecture →
  • Runs inside your own infrastructure. Nothing is uploaded as part of normal Trial operation.
  • No weights, activations, gradients, or training data leave your environment.
  • Makes no network connections. No telemetry, analytics, or phone-home licensing checks.
  • The Trial build ships with no intervention capability. It cannot touch gradients, optimizer state, checkpoints, learning rate, or execution.
  • The proprietary detection logic is distributed as a separately-supplied compiled wheel (aegis-trial-core), not exposed in the public SDK.
  • Full AEGIS's intervention capability, when licensed, is policy-controlled and bounded per client.
  • Local execution reduces exposure, but it isn't a substitute for your own institutional security review. The threat model doesn't cover an already-compromised host.

Full documentation: Threat Model · Data Flow · Privacy

05
The Product, In Practice

See the event before the damage compounds.

AEGIS watches internal training telemetry for a training-state transition. In a prospective study, it distinguished a synthetic induced event from clean controls, using a threshold frozen before the run started.

AEGIS Event Detected Prospective study result
StudyFive-fresh-seed exact-prefix validation
Seed74209
EventSynthetic induced transition
Clean control armNo rings detected
Event armRings detected, steps 176-178
Operational contractPassed, 5 of 5 fresh seeds
Action takenNone. Detection-only study.
Real result from a prospective, frozen-threshold study against synthetic induced events. Five seeds; a bounded validation, not yet a large-scale production claim.
Some training failures are preceded by detectable changes in internal training dynamics.
The premise AEGIS is built to test
06
Evidence

Built on observed training behavior,
not a theoretical promise.

Every claim below is labeled at the confidence level it has actually earned, and grouped by what it actually validates: the current Trial's detection, Full AEGIS's controlled intervention, or an earlier implementation's historical benchmark. Nothing here is presented as a universal guarantee.

Detection evidence · what the current Trial measures
5/5
Fresh-seed validation passes
Prospective study · frozen threshold, fixed before the run · vs. clean exact-prefix controls
0
False triggers in the clean control arm
Same five-seed study · e.g. seed 74209: no rings in the clean arm, event rings at steps 176-178
Governance evidence · what Full AEGIS adds
4/4
Controlled runs where AEGIS localized and quarantined the faulty worker
Worker-local fault study · downstream benefit positive in all four · directional confirmation, not a statistical-significance claim
Gradient quarantine · first smoke run vs. theoretical ceiling
First smoke run · full exclusion58.3%
Theoretical maximum · perfect oracle exclusion98.6%
58.3% reaches 59% of the oracle ceiling on the first single-run smoke test. Superseded above by the rank-balanced 4/4 confirmation across seeds.
Two of the four runs above carry a numerical-repeatability qualification, noted here rather than folded into the headline number. Four independent seed-level wins are compelling directional replication, not a conventional statistical-significance claim.
Anti-hallucination protocol · confidence tier: directional
Historical evidence · an earlier AEGIS implementation
4.309%
Wall-clock reduction, founder-reported
Qwen3-1.7B / FineWeb-Edu · 10-seed cohort, 7 step wins / 3 draws / 0 losses · not independently validated · not shown to outperform a lower-learning-rate control
1,308
Training runs in the historical dataset
4 model families · broader context from the same earlier implementation · not the basis for the 4.309% figure specifically, and not a validation of the current detector

An earlier vision-domain test (ResNet-50 / CIFAR-10) showed an early signal from this implementation. A later calibration pass found the frozen detector unreliable across seeds, so it isn't presented here as a confirmed result.

Known boundaries: the 4.309% figure is founder-reported, not independently validated, came from an earlier AEGIS implementation, and hasn't been shown to outperform a simple lower-learning-rate control, so it's kept as historical context, not the economic case for the Trial. An identified activation-capture limitation in those runs means they support the reported timing observation only, not claims about detector mechanism or geometry. The worker-localization result is real, controlled, and directional, four seeds is compelling replication, not a conventional significance claim. The five-seed detection study is prospective and synthetic. Nothing here is presented as broader than the study that produced it.
Anti-hallucination protocol · confirmed, directional, and historical claims kept separate
See methodology →     Read the technical white paper (PDF) →
07
What You Get Back

Your AEGIS Trial report.

At the end of a Trial, AEGIS generates an evaluation report built from your own runs, not ours.

Sample Trial Report Illustrative layout · populated from your data
14
Runs monitored
7
Events detected
5
Preceded real degradation
412
Median lead, in steps
3
Caught before existing alerting
The question a Trial answers isn't "did AEGIS save compute." It's: what did AEGIS show you that your existing monitoring didn't?
08
Beyond the Trial

Detection is only the first step.

AEGIS Trial
Observe.
Detection-only. Local. No intervention capability. Free.
→
Full AEGIS
Detect. Govern. Intervene.
The commercial system supports bounded, policy-controlled intervention, configured to your workflow and risk tolerance.

The full system runs on a two-stage protection ontology, designed to reduce false positives by requiring corroborating evidence before anything touches your training run:

01
Signal
Internal telemetry detects a training-state transition. Governance arms, without disrupting the run.
→
02
Confirmation
Immediate performance evidence is checked for corroboration that the detected transition is associated with degradation.
→
03
Action
Only when both stages fire does intervention begin. The method is configurable per client.
09
The Platform

AEGIS is one layer of Pyper3.

Pyper³ is building training-governance infrastructure across the AI development lifecycle. AEGIS is the production entry point, with replicated results behind it. The rest of the pipeline is labeled at the maturity it has actually earned.

Early Pilot
RE:F/NED
Govern what enters. Pre-ingestion data quality scoring, before training starts.
Confirmed · Early access
AEGIS
Govern what forms. Real-time governance on training dynamics, inside the run.
In Build
conxiOS
Govern what emerges. Inference-layer alignment, downstream of training.
Research
I:AM
Govern longitudinal agency preservation. An influence-aware mediator.
Get Started

See what AEGIS finds
in your training run.

Free. Local. Detection-only.

Read the Docs
No weights, activations, gradients, or training data leave your environment.