One trusted identity. Owned by you. Accepted everywhere.
Aegis ID is a digital identity platform that lets people prove who they are, sign for what they approve, and carry a single verified identity across every agency, app, and organization — without a password sprawl and without handing control to anyone else.
Vanguard Cloud Services · Aegis IDA non-technical guide · Authentication · Authorization · Digital Signatures
The idea in one minute
What is Aegis ID?
Think of Aegis ID as a secure digital wallet for your identity — the online equivalent of the cards in your physical wallet, but tamper-proof, instantly verifiable, and impossible to forge.
Today your identity is scattered across dozens of systems. Every agency, employer, and application keeps its own copy of "you" — its own username, its own password, its own record. That is expensive to run, painful to use, and a magnet for attackers.
Aegis ID flips the model. Instead of every organization storing a copy of your identity, you hold verified credentials in your own wallet — on your phone — and present them only when needed. This approach is known as decentralized identity, built on an open standard called a DID (a Decentralized Identifier): a private, unforgeable digital ID that belongs to you, not to a vendor.
The plain version: A trusted issuer (say, your government or employer) gives you a digital credential. It lives in your Aegis wallet. When someone needs to check it, they verify it in seconds — cryptographically, with certainty — and they never have to store your personal data to do it.
Why this matters
The problem: identity sprawl
Consider a contractor working across the federal government. To do their job they may need access to five different agencies — and today that means:
Five separate accounts, each with its own onboarding, vetting, and paperwork.
Five sets of credentials — usernames, passwords, smartcards, one-time codes — to remember and protect.
Weeks of delay as each agency independently re-verifies the same identity that another agency already confirmed.
No clean off-switch. When the contract ends, someone has to remember to disable all five accounts. Any that are missed become an open door.
Multiply that by thousands of employees and contractors, across every organization, and you get the status quo: costly, slow, frustrating, and — worst of all — insecure.
One person carries a single verified identity — presented on demand, accepted everywhere, with no duplicate accounts to manage or forget.
The technology, without the jargon
How it works: the trust triangle
Every verifiable credential involves three simple roles. Aegis ID orchestrates all three and adds the security, policy, and evidence around them.
01 · ISSUERGrants the credentialA trusted authority — a government body, employer, or certification agency — signs a digital credential confirming a fact about you (your role, clearance, or membership).
02 · HOLDERCarries it — that's youThe credential lands in your Aegis wallet on your phone. You own it. Nobody can use it without your approval, and you decide exactly what to share.
03 · VERIFIERChecks it instantlyAny app or agency can confirm the credential is genuine and unrevoked in seconds — mathematically certain, without calling the issuer or storing your data.
The issuer and verifier never have to talk to each other. They both trust the cryptographic anchor — and Aegis records the whole exchange on a tamper-proof ledger.
Who is in control
Data sovereignty: your identity stays yours
In the old model, every organization hoards a copy of your personal data. Each copy is a liability — a target for breaches and a loss of control for you. Aegis ID is built on the opposite principle.
You hold itYour credentials live in your wallet, on your device, under your control — not in a vendor's central database.
You share only what's neededProve you're over 18, or cleared to level 3, without revealing your birth date or full record. Share the fact, not the file.
No central honeypotThere is no giant database of everyone's identity for attackers to steal. The risk is distributed, not concentrated.
Data residency respectedDeployments run in the environments and jurisdictions you require — local, dev, QA, and production — across your own tenants.
This is the heart of decentralized identity: selective disclosure and self-custody. Organizations get the assurance they need; individuals keep control of what they reveal.
What a DID unlocks
Authentication, authorization & digital signatures
A single verified identity powers three everyday needs that are usually handled by three different, disconnected systems:
AUTHENTICATIONProving who you areSign in without passwords using your wallet plus a fingerprint, face, or hardware key. Phishing-resistant by design — there's no password to steal.
AUTHORIZATIONProving what you may doAegis is the single decision point. Every request is checked against central policy and role-based rules — deny by default, allow only what's permitted.
SIGNATURESProving what you approvedApprove a payment, a document, or a sensitive action from your wallet. The result is a legally meaningful, cryptographically signed record that can't be repudiated.
One identity, three jobs. Because it's the same trusted wallet behind all three, a person's experience becomes: unlock the phone, review the request, approve. That's it.
Trust you can audit
Immutability: an evidence trail that can't be altered
Every meaningful action — a credential issued, an approval given, a signature made — is written to an immutable ledger. Immutable means it can be added to but never quietly changed or erased. Each record is chained to the one before it, so any tampering is instantly obvious.
Non-repudiation: nobody can later deny an action they approved — the signed evidence stands on its own.
Effortless audit: compliance and investigations get a complete, trustworthy history instead of scattered logs.
Tamper-evident by construction: altering one record would break the chain and be caught immediately.
Every action becomes a permanent, verifiable link in the chain — the foundation for audit, compliance, and non-repudiation.
The off-switch that actually works
Revocation: shut the door instantly, everywhere
The hardest part of security isn't granting access — it's removing it. When someone changes roles, leaves, or a device is lost, every door they could open needs to close at once. In the old model that means chasing down accounts across many systems, and any one that's missed is a breach waiting to happen.
With Aegis ID, access flows from a credential you control centrally. Revoke it once, and it stops working everywhere the next time it's checked. No orphaned accounts. No lingering back doors.
1 action
Revoke a credential in a single step
Seconds
Access ends at the next verification, not next week
0 orphans
No forgotten accounts left quietly open
Why it matters: the moment a contractor's engagement ends or a device goes missing, unauthorized access is eliminated — not scheduled, not hoped for. Provably, immediately, and recorded on the ledger.
Losing a phone is not losing your identity
Recovery: your identity survives the device
People change phones and lose them. In most systems that means starting over — re-proving who you are to every organization all over again. Aegis ID is built so that the device is replaceable and the identity is not.
Nothing sensitive is ever backed up — there is no secret file or recovery phrase to leak. Instead, recovery re-binds your existing identity to your new phone. Crucially, your Wallet ID stays the same, so you never have to tell your organizations anything changed.
EVERYDAYRecovery codesYou receive ten single-use codes at setup. One code plus a verification message to your registered email or phone restores your wallet.
LOST CODESYour organization vouchesAn administrator re-verifies you the same way they did on day one — in person or with photo ID — and restores their organization's credentials.
PROTECTEDHighest-value access pausesSelf-service recovery deliberately leaves the most sensitive credentials suspended until a person confirms your identity.
Why the safeguards matter: account recovery is how most real-world takeovers happen. Aegis requires two independent factors for self-service recovery, revokes the old device immediately, freezes contact changes afterwards, and writes every step to the immutable ledger — so a fraudulent attempt is both hard to complete and impossible to hide.
One identity, many doors
Portability: verify once, be trusted across organizations
Because the identity belongs to the person — not to any single system — it travels with them. An identity verified for one agency can be accepted by another without starting the vetting process over. That is the end of "identity sprawl" from the earlier example.
The same wallet opens every door the person is entitled to — no re-vetting, no duplicate onboarding, no new password for each destination.
Works with what you already run
Integrations it supports
Aegis ID is a standalone platform — but it's designed to fit into existing environments rather than replace them overnight. It connects upward to enterprise identity providers, downward to the apps that rely on it, and outward to hardware and open standards.
Microsoft Entra IDFederate with existing Azure AD / Entra directories
Microsoft Verified IDIssue & verify standards-based credentials
Okta · Ping · KeycloakUpstream federation to enterprise IdPs
OIDC & OAuth 2.0Aegis-issued sign-in for connected apps
iOS & Android walletCompanion apps for approvals & signatures
Integrations are adapters, not the product. Aegis ID stays the policy decision point and the source of truth; the connectors simply let it meet people and systems where they already are.
Where it delivers
Use cases
Scenario
What Aegis ID does
Federal workforce & contractors
One verified identity accepted across agencies; instant revocation when engagements end.
Cross-agency collaboration
Partner staff prove clearance and role without each agency re-vetting them.
High-value approvals
Wallet-signed authorization for payments, releases, and sensitive actions, with ledger evidence.
Passwordless workforce sign-in
Phishing-resistant access using passkeys and hardware keys instead of passwords.
Credential issuance & consent
Issue employee, membership, or eligibility credentials people carry and control.
Regulated & audited environments
Immutable evidence for every action supports compliance and investigations.
What it feels like to use
User journeys
Journey 1 New contractor onboarding — days, not weeks
Verify once.The contractor is vetted a single time and receives a verified credential in their Aegis wallet.
Walk in the door.At each agency they present the credential from their phone — no new account, no new password.
Get to work.Aegis checks policy and role in real time and grants exactly the access they're entitled to.
Engagement ends.The credential is revoked once. Access closes everywhere at the next check — automatically.
Journey 2 Passwordless sign-in to a connected app
Open the app.Instead of a password box, the app asks Aegis to confirm the person.
Approve on your phone.A prompt appears in the wallet; a fingerprint or face unlock approves it.
You're in.Aegis issues a secure session. Nothing to type, nothing to phish.
Journey 3 Approving a sensitive action with a digital signature
Action requested.A payment or document release triggers a wallet challenge with the full details.
Review & decide.The person sees exactly what they're approving and taps approve or decline — both are meaningful and recorded.
Signed & sealed.An approval produces a cryptographic signature written to the immutable ledger as permanent evidence.
The bottom line
Why Aegis ID matters
For peopleOne identity, no password sprawl, full control over what's shared, and a wallet that just works.
For organizationsFaster onboarding, lower cost, centralized policy, and instant, provable revocation.
For security teamsDeny-by-default enforcement, phishing-resistant sign-in, and no central honeypot to defend.
For auditorsA complete, tamper-proof evidence trail for every credential, approval, and signature.
Aegis ID turns identity from a scattered liability into a single, portable, verifiable asset — owned by the individual, trusted by every organization, and provable for all time.