Trust & Security
Aegis is offensive-security software: to test your application it holds sensitive things — the credentials you supply for authenticated testing, your scan configuration, and the findings we discover. This page states plainly how we protect them, who we share data with, and — honestly — where we are on our own security assurance.
Straight answer on certifications: Aegis is not yet SOC 2 or ISO 27001 certified. Formal third-party assurance is on our roadmap. Below are the controls we operate today; we would rather tell you exactly what is and isn't in place than imply a badge we don't hold.
1. Sub-processors
We keep the list short on purpose. We do not sell personal data, and we share only what each provider needs to do its job.
| Sub-processor | Purpose | Data it handles |
|---|---|---|
| DigitalOcean | Application hosting & compute (the scanner, database, workers) | All service data at rest (encrypted); processed in the region configured for your workspace |
| Stripe | Payments & subscription billing | Billing details and card data — handled by Stripe; we never store full card numbers |
| Resend | Transactional email (verification, password reset, report-ready) | Recipient email address and message content; DKIM/SPF-authenticated from aegisbackbone.com |
| Cloudflare | DNS for aegisbackbone.com | DNS resolution only (DNS-only mode); no application traffic is proxied |
2. What we store, and how it's protected
- In transit: everything is served over HTTPS (TLS 1.3), with HSTS and HTTP→HTTPS upgrade.
- At rest: data is stored encrypted, scoped to your workspace.
- Credentials you supply for authenticated testing are stored encrypted in a credential vault and are never returned in readable form.
- Evidence is redacted server-side before storage, so captured request/response evidence doesn't retain more than it needs.
- Tenant isolation: each workspace's data, scans and reports are isolated from every other tenant — a property we continuously test on our own platform (see Proof).
3. Data retention
While your account is active, scan reports and findings are retained for up to 18 months so you have a running security history for auditors. You can export or delete your data at any time. On termination we delete or return your data within 30 days, save for backups purged on their ordinary cycle and records we must keep by law. Full detail is in our Privacy Policy.
4. Access & authentication
- Work email required — accounts (and MFA) require a business email address, not a free consumer provider.
- Multi-factor authentication (TOTP, with QR enrolment) is available on every account.
- One-time secrets — API keys and private-agent enrolment tokens are shown once and stored only as SHA-256 hashes; they are not recoverable from us.
- Support access to a tenant is approved, time-limited and secret-blind by design.
5. Scanning safeguards
Aegis runs offensive traffic, so it is built to fail safe:
- Ownership verification — you must prove control of a target via DNS before any test runs, and accept the Rules of Engagement.
- Non-destructive by default — baseline and authenticated tiers are non-destructive and rate-limited, safe to run against production.
- State-changing / heavier tests run only against non-production targets you designate, or opt-in behind explicit consent; an emergency stop is always available.
- Bounded — every scan runs under request- and mutation-budgets and a rate limit; provider infrastructure is never tested.
- Edge guard — the production API enforces HTTPS, an allow-listed Host, and trusted-proxy checks.
6. Our own security posture
We hold ourselves to the controls above and dogfood the product: we run Aegis's full aggressive suite against Aegis's own production on every meaningful change and publish the result, including the hardening items it flagged and we fixed — see Proof. What we operate today: encryption in transit and at rest, tenant isolation, MFA, least-privilege and one-time secrets, a disposable scan plane, and server-side evidence redaction. What we do not yet have: a completed SOC 2 Type II or ISO 27001 audit — these are on our roadmap, and we'll publish them here when they land.
7. Responsible disclosure
We welcome good-faith security research. Our machine-readable policy is at /.well-known/security.txt. Report a vulnerability to aegis.security@backbonesolutions.ca; we aim to acknowledge within one business day and will not pursue legal action against researchers acting in good faith (test only your own account, don't access other customers' data, don't degrade the service, give us reasonable time to remediate).
8. Data residency
Your workspace is assigned a home region and data is processed there; regional controls govern where scans and storage run. Ask us if you have a specific residency requirement.
9. Contact
Security: aegis.security@backbonesolutions.ca · General/privacy: aegis.support@backbonesolutions.ca · Backbone Business Solutions Inc., incorporated in British Columbia, Canada (incorporation number BC1601923), operator of the Aegis service.