Vulnerability Disclosure Policy

How to report security vulnerabilities in AegisGate products. We follow RFC 9116 and offer coordinated disclosure with a 90-day timeline.

Vulnerability Disclosure Policy

Last updated: 2026-07-29 Policy owner: AegisGate Security, LLC Contact: security@aegisgatesecurity.io PGP key: SECURITY.md

AegisGate Security, LLC takes security vulnerabilities seriously. This policy describes how to report vulnerabilities, what to expect, and our commitments to researchers.


Our Commitments

  1. We will acknowledge your report within 24 hours.
  2. We will triage your report within 72 hours and provide an initial assessment.
  3. We will not pursue legal action against researchers who follow this policy.
  4. We will credit researchers in our security advisories (unless you request anonymity).
  5. We follow coordinated disclosure with a 90-day timeline (see below).

How to Report

Option 1: Email (Preferred)

Send your report to security@aegisgatesecurity.io.

For sensitive reports, encrypt with our PGP key (fingerprint: 97C0 418A DBE0 5396), available at:

Option 2: GitHub Security Advisory

For vulnerabilities in open-source repositories, use GitHub’s private vulnerability reporting:

Option 3: CVE-for-AI Feed

For AI-specific vulnerabilities (prompt injection, model manipulation, adversarial attacks), you may also submit via our CVE-for-AI feed. See AEGIS-2026-0001 for an example of how we publish AI vulnerability disclosures.


What to Include

Please include as much of the following as possible:

ItemDescription
Vulnerability descriptionClear description of the issue and its impact
Affected productAegisGate Platform, Lens, or website
Affected versionVersion number or commit hash
Reproduction stepsStep-by-step instructions to reproduce the issue
Proof of conceptCode, screenshots, or network traces demonstrating the vulnerability
Impact assessmentWhat an attacker could achieve (data access, privilege escalation, etc.)
Suggested fixIf you have ideas for how to fix the issue
Your contact infoEmail, GitHub handle, or other preferred contact method

Scope

In Scope

ProductScope
AegisGate PlatformAll code in aegisgate-platform repository, including API, CLI, compliance modules, and Docker images
AegisGate LensAll code in aegisgate-lens repository, including the browser extension and backend
aegisgatesecurity.ioThe corporate website (Hugo static site)
InfrastructureDNS, TLS certificates, and publicly accessible endpoints

Out of Scope

  • Social engineering attacks against AegisGate employees or contractors
  • Physical attacks against AegisGate infrastructure
  • Denial of service attacks (we ask that you do not test these without prior authorization)
  • Vulnerabilities in third-party services (Stripe, Cloudflare, Netlify, GitHub) — report these to the respective providers
  • Issues in dependencies that are already known and have available patches
  • Best practice issues (missing headers, verbose errors) without demonstrable security impact

Coordinated Disclosure Timeline

We follow a 90-day coordinated disclosure timeline:

DayMilestone
Day 0Vulnerability reported to security@aegisgatesecurity.io
Day 1Acknowledgment sent to reporter
Day 3Initial triage and severity assessment completed
Day 7Fix developed and tested internally
Day 14Fix released in a new version (for critical/high severity)
Day 30Fix released (for medium/low severity)
Day 90Public disclosure (if not already released)

Exceptions

  • Active exploitation: If a vulnerability is being actively exploited, we may disclose earlier than 90 days to protect users.
  • Reporter request: If the reporter requests a shorter or longer timeline, we will accommodate reasonable requests.
  • Complex fixes: If a fix requires significant changes, we may extend the timeline with the reporter’s agreement.

Severity Classification

We use the Common Vulnerability Scoring System (CVSS) v3.1:

SeverityCVSS RangeResponse TimeExample
Critical9.0–10.024 hoursRemote code execution without authentication
High7.0–8.972 hoursPrivilege escalation, sensitive data exposure
Medium4.0–6.914 daysXSS with user interaction, CSRF
Low0.1–3.930 daysInformation disclosure with limited impact

Safe Harbor

AegisGate Security, LLC considers research conducted under this policy to be authorized testing and will not pursue civil or criminal legal action against researchers who:

  1. Act in good faith to identify and report vulnerabilities
  2. Do not access, modify, or delete data belonging to others
  3. Do not degrade or disrupt AegisGate services
  4. Do not publicly disclose the vulnerability before the coordinated disclosure timeline expires
  5. Provide AegisGate reasonable time to remediate the issue before public disclosure

Bounty Program

AegisGate Security, LLC does not currently operate a paid bug bounty program. However, we are committed to:

  • Public credit in our security advisories and CVE disclosures
  • Swag (AegisGate-branded merchandise) for confirmed vulnerabilities
  • Early access to new features for researchers who find significant vulnerabilities

If you are interested in a paid bounty program, please contact security@aegisgatesecurity.io. We are exploring options for a formal program.


Supported Versions

ProductVersionSupport Status
AegisGate Platformv4.1.x✅ Current release
AegisGate Platformv4.0.x✅ Active support
AegisGate Platformv4.1.x⚠️ Critical fixes only
AegisGate Platformv3.5.x⛔ End of life
AegisGate Platformv3.4.x⛔ End of life
AegisGate Platformv3.3.x⛔ End of life
AegisGate Rampartv0.7.1✅ Current release
AegisGate Lensv0.4.1✅ Current release
AegisGate Lensv0.4.1⚠️ Critical fixes only
AegisGate Lensv0.1.x⛔ End of life

CVE-for-AI Feed

AegisGate publishes AI-specific vulnerability disclosures through our CVE-for-AI feed at /cve/. This feed covers:

  • Prompt injection vulnerabilities
  • AI model manipulation
  • Adversarial attacks against AI systems
  • Training data poisoning
  • Model extraction and data leakage

See AEGIS-2026-0001 for our first published advisory.


Contact

ChannelPurpose
security@aegisgatesecurity.ioVulnerability reports (PGP-encrypted preferred)
GitHub Security Advisory (Platform)Open-source vulnerability reports
GitHub Security Advisory (Lens)Open-source vulnerability reports
X/Twitter@aegisgate
Mastodon@aegisgate@mastodon.social

AegisGate Security, LLC follows RFC 9116 for security.txt and vulnerability disclosure. Our security.txt is available at aegisgatesecurity.io/.well-known/security.txt.