Aegis ID
Identity · Wallet · Credentials
Decentralized Identity Platform · Plain-language overview

One trusted identity.
Owned by you. Accepted everywhere.

Aegis ID is a digital identity platform that lets people prove who they are, sign for what they approve, and carry a single verified identity across every agency, app, and organization — without a password sprawl and without handing control to anyone else.

Vanguard Cloud Services · Aegis ID A non-technical guide · Authentication · Authorization · Digital Signatures
The idea in one minute

What is Aegis ID?

Think of Aegis ID as a secure digital wallet for your identity — the online equivalent of the cards in your physical wallet, but tamper-proof, instantly verifiable, and impossible to forge.

Today your identity is scattered across dozens of systems. Every agency, employer, and application keeps its own copy of "you" — its own username, its own password, its own record. That is expensive to run, painful to use, and a magnet for attackers.

Aegis ID flips the model. Instead of every organization storing a copy of your identity, you hold verified credentials in your own wallet — on your phone — and present them only when needed. This approach is known as decentralized identity, built on an open standard called a DID (a Decentralized Identifier): a private, unforgeable digital ID that belongs to you, not to a vendor.

The plain version: A trusted issuer (say, your government or employer) gives you a digital credential. It lives in your Aegis wallet. When someone needs to check it, they verify it in seconds — cryptographically, with certainty — and they never have to store your personal data to do it.
Why this matters

The problem: identity sprawl

Consider a contractor working across the federal government. To do their job they may need access to five different agencies — and today that means:

Multiply that by thousands of employees and contractors, across every organization, and you get the status quo: costly, slow, frustrating, and — worst of all — insecure.

TODAY — ONE PERSON, MANY LOGINS You Agency A login Agency B login Agency C login Agency D login Agency E login WITH AEGIS ID — ONE VERIFIED WALLET You Aegis Wallet Agency A Agency B–D Agency E
One person carries a single verified identity — presented on demand, accepted everywhere, with no duplicate accounts to manage or forget.
The technology, without the jargon

How it works: the trust triangle

Every verifiable credential involves three simple roles. Aegis ID orchestrates all three and adds the security, policy, and evidence around them.

01 · ISSUERGrants the credentialA trusted authority — a government body, employer, or certification agency — signs a digital credential confirming a fact about you (your role, clearance, or membership).
02 · HOLDERCarries it — that's youThe credential lands in your Aegis wallet on your phone. You own it. Nobody can use it without your approval, and you decide exactly what to share.
03 · VERIFIERChecks it instantlyAny app or agency can confirm the credential is genuine and unrevoked in seconds — mathematically certain, without calling the issuer or storing your data.
ISSUER Gov / Employer signs the credential VERIFIER App / Agency checks it instantly HOLDER — YOU Aegis Wallet approve / decline issue credential present proof trusts the same anchor — no back-channel needed Aegis policy engine + immutable evidence ledger
The issuer and verifier never have to talk to each other. They both trust the cryptographic anchor — and Aegis records the whole exchange on a tamper-proof ledger.
Who is in control

Data sovereignty: your identity stays yours

In the old model, every organization hoards a copy of your personal data. Each copy is a liability — a target for breaches and a loss of control for you. Aegis ID is built on the opposite principle.

You hold itYour credentials live in your wallet, on your device, under your control — not in a vendor's central database.
You share only what's neededProve you're over 18, or cleared to level 3, without revealing your birth date or full record. Share the fact, not the file.
No central honeypotThere is no giant database of everyone's identity for attackers to steal. The risk is distributed, not concentrated.
Data residency respectedDeployments run in the environments and jurisdictions you require — local, dev, QA, and production — across your own tenants.
This is the heart of decentralized identity: selective disclosure and self-custody. Organizations get the assurance they need; individuals keep control of what they reveal.
What a DID unlocks

Authentication, authorization & digital signatures

A single verified identity powers three everyday needs that are usually handled by three different, disconnected systems:

AUTHENTICATIONProving who you areSign in without passwords using your wallet plus a fingerprint, face, or hardware key. Phishing-resistant by design — there's no password to steal.
AUTHORIZATIONProving what you may doAegis is the single decision point. Every request is checked against central policy and role-based rules — deny by default, allow only what's permitted.
SIGNATURESProving what you approvedApprove a payment, a document, or a sensitive action from your wallet. The result is a legally meaningful, cryptographically signed record that can't be repudiated.
One identity, three jobs. Because it's the same trusted wallet behind all three, a person's experience becomes: unlock the phone, review the request, approve. That's it.
Trust you can audit

Immutability: an evidence trail that can't be altered

Every meaningful action — a credential issued, an approval given, a signature made — is written to an immutable ledger. Immutable means it can be added to but never quietly changed or erased. Each record is chained to the one before it, so any tampering is instantly obvious.

IMMUTABLE EVIDENCE LEDGER BLOCK 01 Credential issued hash · 09:14 UTC BLOCK 02 Access approved hash · 11:02 UTC BLOCK 03 Document signed hash · 14:37 UTC BLOCK 04 Access revoked hash · 16:20 UTC Each block carries the fingerprint of the one before it — the chain cannot be rewritten.
Every action becomes a permanent, verifiable link in the chain — the foundation for audit, compliance, and non-repudiation.
The off-switch that actually works

Revocation: shut the door instantly, everywhere

The hardest part of security isn't granting access — it's removing it. When someone changes roles, leaves, or a device is lost, every door they could open needs to close at once. In the old model that means chasing down accounts across many systems, and any one that's missed is a breach waiting to happen.

With Aegis ID, access flows from a credential you control centrally. Revoke it once, and it stops working everywhere the next time it's checked. No orphaned accounts. No lingering back doors.

1 action
Revoke a credential in a single step
Seconds
Access ends at the next verification, not next week
0 orphans
No forgotten accounts left quietly open
Why it matters: the moment a contractor's engagement ends or a device goes missing, unauthorized access is eliminated — not scheduled, not hoped for. Provably, immediately, and recorded on the ledger.
Losing a phone is not losing your identity

Recovery: your identity survives the device

People change phones and lose them. In most systems that means starting over — re-proving who you are to every organization all over again. Aegis ID is built so that the device is replaceable and the identity is not.

Nothing sensitive is ever backed up — there is no secret file or recovery phrase to leak. Instead, recovery re-binds your existing identity to your new phone. Crucially, your Wallet ID stays the same, so you never have to tell your organizations anything changed.

EVERYDAYRecovery codesYou receive ten single-use codes at setup. One code plus a verification message to your registered email or phone restores your wallet.
LOST CODESYour organization vouchesAn administrator re-verifies you the same way they did on day one — in person or with photo ID — and restores their organization's credentials.
PROTECTEDHighest-value access pausesSelf-service recovery deliberately leaves the most sensitive credentials suspended until a person confirms your identity.
Why the safeguards matter: account recovery is how most real-world takeovers happen. Aegis requires two independent factors for self-service recovery, revokes the old device immediately, freezes contact changes afterwards, and writes every step to the immutable ledger — so a fraudulent attempt is both hard to complete and impossible to hide.
One identity, many doors

Portability: verify once, be trusted across organizations

Because the identity belongs to the person — not to any single system — it travels with them. An identity verified for one agency can be accepted by another without starting the vetting process over. That is the end of "identity sprawl" from the earlier example.

ONE VERIFIED IDENTITY carried in your Aegis wallet Federal Agency Contractor Portal Partner Org Cloud App
The same wallet opens every door the person is entitled to — no re-vetting, no duplicate onboarding, no new password for each destination.
Works with what you already run

Integrations it supports

Aegis ID is a standalone platform — but it's designed to fit into existing environments rather than replace them overnight. It connects upward to enterprise identity providers, downward to the apps that rely on it, and outward to hardware and open standards.

Microsoft Entra IDFederate with existing Azure AD / Entra directories
Microsoft Verified IDIssue & verify standards-based credentials
Okta · Ping · KeycloakUpstream federation to enterprise IdPs
OIDC & OAuth 2.0Aegis-issued sign-in for connected apps
SAMLDownstream relying-party integration
WebAuthn & PasskeysPasswordless, phishing-resistant sign-in
YubiKeyHardware-backed high-assurance authentication
Hyperledger AriesOpen decentralized-identity credential exchange
iOS & Android walletCompanion apps for approvals & signatures
Integrations are adapters, not the product. Aegis ID stays the policy decision point and the source of truth; the connectors simply let it meet people and systems where they already are.
Where it delivers

Use cases

ScenarioWhat Aegis ID does
Federal workforce & contractorsOne verified identity accepted across agencies; instant revocation when engagements end.
Cross-agency collaborationPartner staff prove clearance and role without each agency re-vetting them.
High-value approvalsWallet-signed authorization for payments, releases, and sensitive actions, with ledger evidence.
Passwordless workforce sign-inPhishing-resistant access using passkeys and hardware keys instead of passwords.
Credential issuance & consentIssue employee, membership, or eligibility credentials people carry and control.
Regulated & audited environmentsImmutable evidence for every action supports compliance and investigations.
What it feels like to use

User journeys

Journey 1 New contractor onboarding — days, not weeks
  1. Verify once. The contractor is vetted a single time and receives a verified credential in their Aegis wallet.
  2. Walk in the door. At each agency they present the credential from their phone — no new account, no new password.
  3. Get to work. Aegis checks policy and role in real time and grants exactly the access they're entitled to.
  4. Engagement ends. The credential is revoked once. Access closes everywhere at the next check — automatically.
Journey 2 Passwordless sign-in to a connected app
  1. Open the app. Instead of a password box, the app asks Aegis to confirm the person.
  2. Approve on your phone. A prompt appears in the wallet; a fingerprint or face unlock approves it.
  3. You're in. Aegis issues a secure session. Nothing to type, nothing to phish.
Journey 3 Approving a sensitive action with a digital signature
  1. Action requested. A payment or document release triggers a wallet challenge with the full details.
  2. Review & decide. The person sees exactly what they're approving and taps approve or decline — both are meaningful and recorded.
  3. Signed & sealed. An approval produces a cryptographic signature written to the immutable ledger as permanent evidence.
The bottom line

Why Aegis ID matters

For peopleOne identity, no password sprawl, full control over what's shared, and a wallet that just works.
For organizationsFaster onboarding, lower cost, centralized policy, and instant, provable revocation.
For security teamsDeny-by-default enforcement, phishing-resistant sign-in, and no central honeypot to defend.
For auditorsA complete, tamper-proof evidence trail for every credential, approval, and signature.

Aegis ID turns identity from a scattered liability into a single, portable, verifiable asset — owned by the individual, trusted by every organization, and provable for all time.