Security

Vulnerability Disclosure Policy

Last updated: June 2026. We welcome reports from security researchers. This policy explains how to report a vulnerability, what you can expect from us, and the boundaries that keep patient data safe. It is informational and does not create contractual obligations.

1. How to Report

Email support@aegisbiocryption.com. Please include a clear description of the issue, the steps to reproduce it, and the potential impact. Our machine-readable contact is published at /.well-known/security.txt.

2. Do Not Include PHI

Aegis is a HIPAA Business Associate. If a finding may expose Protected Health Information (“PHI”), do not retrieve, store, or transmit that data. Describe the access path and stop; we will reproduce it internally against synthetic data. Never test against real patient studies.

3. Our Commitment

We aim to acknowledge your report within 3 business days, keep you updated on remediation, and credit you (with your permission) once a fix ships. We will not pursue legal action against researchers who act in good faith and in accordance with this policy.

4. Safe Harbor (Good-Faith Research)

Activities conducted consistent with this policy are considered authorized. Good faith means: you avoid privacy violations, data destruction, and service degradation; you only interact with accounts you own or have explicit permission to test; you do not exfiltrate data; and you give us a reasonable time to remediate before any public disclosure.

5. Out of Scope

Denial-of-service, social engineering of staff or customers, physical attacks, spam, and findings that require a compromised device or a man-in-the-middle position you control are out of scope. Reports from automated scanners without a demonstrated, exploitable impact are also out of scope.

Found something?

Report it to our security team and we'll get back to you.

Email support@aegisbiocryption.com