Security by design
The public website is static, has no user accounts, no application backend, and no third-party analytics. Engagement work is scoped, least-privilege, and documented.
This page states how AegisCore Labs handles information, how to report a security issue, and the limits of what we currently claim.
The public website is static, has no user accounts, no application backend, and no third-party analytics. Engagement work is scoped, least-privilege, and documented.
We ask only for the evidence and context required to perform the agreed work. This site does not collect personal data through forms or trackers.
When technical evidence can be processed in the client environment or on controlled local systems, that option is preferred over unnecessary data movement.
Do not send passwords, API keys, tokens, private keys, dumps of secrets, or production credentials through email or this website. If access is required, it is arranged through a scoped, time-bound channel agreed in the engagement.
If you believe you have found a security issue in AegisCore Labs public properties, email [email protected]. We do not currently operate a public bug bounty.
Every conclusion must be backed by verifiable technical evidence.