Verified identity architecture

Vanguard Cloud Services - Aegis ID

A secure identity assurance service for portable credentials, passkeys, wallet challenges, OIDC/SAML integrations, and cross-organization trust testing.

01 Production adapter
02 Aries lab boundary
live Verified ID mode

Mobile wallet

Install the Aegis ID wallet for testing.

Use the iOS TestFlight beta or Android testing link for business-partner wallet pilots.

Get started

Choose a plan, then create your account.

Your plan decides how many organizations you can run and how many credentials each can issue, so it comes first. A trial needs no card, and you can change your mind on the next page. If you were given a registration code, there is a box for it on the account form.

Trial

Free for 30 days

Try the whole platform for 30 days. No card required.

  • 1 organization
  • 5 credentials per organization

Basic

$49/month

One organization, up to 20 credentials.

  • 1 organization
  • 20 credentials per organization

Pay per credential

$19/month, 3 included then $5 per credential

One organization. Three credentials included, then per credential.

  • 1 organization
  • 3 credentials included, then $5 each

Enterprise

$499/month, 100 included then $3 per credential

Unlimited organizations. 100 credentials included, then per credential.

  • Unlimited organizations
  • 100 credentials included, then $3 each

Already registered? Sign in. Comparing options? See all plans.

Setup walkthrough

A quick guide to onboarding.

Eight steps in the order they actually happen: choose a plan, create the account and the organization, set up the wallet, confirm the root wallets that can recover it, then issue a credential and approve a wallet challenge.

Dual-track model

Production trust stays separate from interoperability research.

Production Track

Enterprise assurance path

Verified credentials, YubiKey/passkeys, OIDC/SAML integrations, wallet challenges, and audit evidence stay in one governed enterprise lane.

  • FIDO2 sign-in
  • Verified ID issuance
  • Presentation callbacks
  • Audit-ready events
Interoperability Track

Aries lab without production coupling

ACA-Py issuer, verifier, mediator, the Aegis ID mobile app, and a VON/Indy dev ledger live in a separate lab boundary.

  • DIDComm
  • AnonCreds
  • Mediator testing
  • Wallet interop

How it fits together

Aegis ID decides. Everything else is an adapter.

Identity can be proven in several ways and consumed by any number of applications. What stays constant is the middle: one place that holds the policy, makes the call, and records the evidence.

Step 1

Prove who you are

Any of these, alone or combined, depending on what the moment is worth.

  • Passkeys and YubiKey Phishing-resistant, hardware-backed
  • Aegis wallet approval Approve or decline from your own device
  • Microsoft Entra ID Links to an existing account, never creates one
  • Verified ID A portable credential presented from Authenticator
  • Password and a code The baseline, never enough on its own
Step 2

Aegis ID decides

Deny by default, enforced server-side, and written down whichever way it goes.

  • Authorization and policy One decision point, not per-application rules
  • Credential issuance Bound to a wallet, revocable, consent recorded
  • Root wallets and recovery The organization can recover itself
  • Evidence ledger Hash-chained and append only
Step 3

Applications act on it

They ask Aegis rather than keeping their own copy of who may do what.

  • Connected apps Aegis-issued OIDC and OAuth
  • Business Expenses Wallet-signed approvals
  • Digital signature Envelope signing with wallet consent
  • Your own applications Any OIDC or SAML relying party

Aegis assurance modes

Choose the right proof for the business moment.

Verified ID, YubiKey/FIDO2, and Aegis wallet challenges can work together or independently depending on the application, risk, and organization policy.

VID

Verified ID credential proof

Use Microsoft Authenticator to present portable employee, contractor, badge, or eligibility credentials.

YK

YubiKey FIDO2 step-up

Use YubiKey 5C NFC for phishing-resistant sign-in, administrator step-up, and sensitive workflow protection.

LOG

Aegis wallet challenge ledger

Capture approval, consent, revocation, promotion, and high-value decision evidence across web apps and portals.

Learn more about the product

See how Aegis ID fits into real identity journeys.

This product brief explains the business value, technical architecture, demo journeys, and where Verified ID, YubiKey, and the Aegis ID mobile app each add assurance.

Identity source Verified credential Wallet decision Audit evidence

Use the brief as an executive-ready overview of the product, assurance patterns, and example integration journeys.

01

Credential proof

Verified credentials present portable employee, contractor, partner, or badge proof across trusted workflows.

02

Hardware assurance

YubiKey and FIDO2 add phishing-resistant proof for sign-in, admin step-up, and sensitive actions.

03

Wallet evidence

The Aegis ID mobile app records approval, consent, revocation, and high-value decision challenges.