Trust is operational, not decorative.

This page states how AegisCore Labs handles information, how to report a security issue, and the limits of what we currently claim.

Security by design

The public website is static, has no user accounts, no application backend, and no third-party analytics. Engagement work is scoped, least-privilege, and documented.

Data minimization

We ask only for the evidence and context required to perform the agreed work. This site does not collect personal data through forms or trackers.

Local-first processing where appropriate

When technical evidence can be processed in the client environment or on controlled local systems, that option is preferred over unnecessary data movement.

No secrets upload policy

Do not send passwords, API keys, tokens, private keys, dumps of secrets, or production credentials through email or this website. If access is required, it is arranged through a scoped, time-bound channel agreed in the engagement.

Responsible disclosure

If you believe you have found a security issue in AegisCore Labs public properties, email [email protected]. We do not currently operate a public bug bounty.

Current limitations

  • AegisCore Labs is a cybersecurity services brand operated from Colombia. This site does not state a corporate incorporation form or tax identification number.
  • We do not publish client names, partnership badges, awards, or certification marks we do not hold.
  • AETHER OS is Private Alpha. It is not a generally available cloud service and is not a guarantee of compliance or security.
  • Framework references (for example ISO 27001, NIST CSF, CIS Controls) describe mapping and assessment practice—not official accreditation.

security@aegiscorelabs.com · privacy@aegiscorelabs.com

Every conclusion must be backed by verifiable technical evidence.