Vulnerability Disclosure Policy
Last updated: June 2026. We welcome reports from security researchers. This policy explains how to report a vulnerability, what you can expect from us, and the boundaries that keep patient data safe. It is informational and does not create contractual obligations.
1. How to Report
Email support@aegisbiocryption.com. Please include a clear description of the issue, the steps to reproduce it, and the potential impact. Our machine-readable contact is published at /.well-known/security.txt.
2. Do Not Include PHI
Aegis is a HIPAA Business Associate. If a finding may expose Protected Health Information (“PHI”), do not retrieve, store, or transmit that data. Describe the access path and stop; we will reproduce it internally against synthetic data. Never test against real patient studies.
3. Our Commitment
We aim to acknowledge your report within 3 business days, keep you updated on remediation, and credit you (with your permission) once a fix ships. We will not pursue legal action against researchers who act in good faith and in accordance with this policy.
4. Safe Harbor (Good-Faith Research)
Activities conducted consistent with this policy are considered authorized. Good faith means: you avoid privacy violations, data destruction, and service degradation; you only interact with accounts you own or have explicit permission to test; you do not exfiltrate data; and you give us a reasonable time to remediate before any public disclosure.
5. Out of Scope
Denial-of-service, social engineering of staff or customers, physical attacks, spam, and findings that require a compromised device or a man-in-the-middle position you control are out of scope. Reports from automated scanners without a demonstrated, exploitable impact are also out of scope.
Found something?
Report it to our security team and we'll get back to you.
Email support@aegisbiocryption.com