Aegis ties every artifact and build node to a hardware identity. If the machine is not trusted, the pipeline stops.
Every runner must prove its boot state and port policy before it can sign or publish artifacts.
Private signing keys live inside the TPM. They never touch disk and can only be used by approved hardware.
Each build produces a hardware-backed attestation log that auditors and downstream consumers can verify.