01
Zero-data-retention commitment
Aegis does not retain client data beyond the engagement lifecycle. Working copies of any artifact containing client information — logs, telemetry exports, configuration dumps, data samples — are destroyed within 30 days of engagement close.
A written destruction attestation, naming the artifacts and the date of destruction, is issued to the client sponsor. This commitment is written into every statement of work and is contractually enforceable.
02
Client-tenancy analysis by default
Wherever technically feasible, analysis is performed inside the client tenancy using read-only credentials scoped to the minimum necessary. Client data does not cross the client control boundary.
Where extraction is unavoidable, the scope, format, destination, encryption method and retention duration are agreed in writing before any data moves.
03
No model training on client data
Client data is never used to train, fine-tune, evaluate or benchmark any Aegis model, tool or internal capability.
No client data is submitted to any third-party model provider or inference endpoint without explicit, documented, per-engagement authorization from the client.
04
Access control and personnel
Access to client environments is provisioned per-engagement, per-individual, and revoked at engagement close. Credentials are never shared between personnel.
- Multi-factor authentication enforced on all internal systems and client-provisioned access
- Role-based access with least-privilege defaults and quarterly entitlement review
- Background screening for all engagement personnel; security clearance where the engagement requires it
- Confidentiality obligations survive termination of employment or contract
05
Secure development practices
This platform is developed under a security-by-design mandate. Controls implemented include:
- Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, Permissions-Policy and HSTS on all responses
- Server-side schema validation on every input boundary — client-side validation is treated as a user-experience affordance only
- Rate limiting on all public form endpoints to mitigate automated abuse and enumeration
- No secrets in source control; all configuration is environment-driven with least-privilege service credentials
06
Resource Vault storage architecture
The Client Resource Vault (Phase 2) is designed so that uploaded content never transits application servers. Uploads are performed directly to object storage using short-lived presigned URLs generated server-side only after an authorization check.
- Magic-byte MIME validation server-side; the browser-supplied Content-Type header is never trusted
- All assets pass an asynchronous automated malware scanning pipeline before publication
- Script execution disabled on storage buckets; Content-Disposition: attachment enforced on delivery
- Row-level security policies govern object visibility; public exposure requires an explicit publish action
- Presigned URL lifetimes are measured in minutes and are single-purpose
07
Vendor independence
Aegis holds no reseller agreements, referral arrangements, or vendor commissions of any kind. No recommendation we make carries a commercial incentive.
This is a control, not a marketing position: it is what allows our findings to be used as evidence by your internal audit and second-line risk functions without a conflict-of-interest disclosure.
08
Incident response
In the event of a security incident affecting client information, we will notify the client sponsor without undue delay and in any case within the timeframe specified in the engagement agreement.
Notification will include the nature of the incident, the categories of information affected, containment actions taken, and remediation steps. We will support the client in meeting their own regulatory notification obligations.
09
Responsible disclosure
If you believe you have identified a security vulnerability in this platform, we ask that you report it privately through the briefing form with "Security Disclosure" in the subject of your message, and allow us reasonable time to remediate before public disclosure.
We do not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and do not exfiltrate data.
Questions
Direct questions regarding this document to your engagement principal, or submit a request through the briefing form. This document is provided for informational purposes and does not constitute legal advice.
