AEGIS Vulnerability Disclosure Policy
Thank you for helping keep AEGIS and its public demo secure.
Report a vulnerability
Use GitHub private vulnerability reporting. Do not open a public issue. Include affected component(s), a minimal reproduction, impact, and the deployment context.
Safe harbor
We support good-faith security research conducted under this policy. We will not pursue legal action for research that avoids privacy violations, service disruption, data destruction, and actions outside this scope. If you are unsure whether a test is permitted, report the concern first and wait for guidance.
Scope
In scope: AEGIS services, SDKs, deployment manifests, and the public demo operated by this project. Report specific, reproducible bypasses even when they concern known detection limitations.
Out of scope: denial-of-service testing, social engineering, physical attacks, third-party services, and accessing, modifying, or deleting data that is not your own.
Response
We aim to acknowledge valid reports within 5 business days. We will coordinate remediation and disclosure with the reporter when contact details are provided.
The canonical repository policy is SECURITY.md. Machine-readable contact information is available at /.well-known/security.txt.