Vulnerability Disclosure Policy
We take security seriously. If you've found a vulnerability in Aegis Firma, we want to know about it so we can fix it and protect our users. This policy explains how to report a vulnerability safely.
Effective date: April 2026 · Version 1.0
48h
Acknowledgment
7 days
Triage & validate
90 days
Fix target (standard)
7 days
Fix target (critical)
How to report
- 1.Email your report to security@aegisfirma.com
- 2.Include: a description of the vulnerability, steps to reproduce, the affected component (URL, API endpoint, feature), and your assessment of the impact.
- 3.Attach screenshots, HTTP request/response logs, or a proof-of-concept if available (do not exploit beyond confirming the issue).
- 4.We will acknowledge your report within 48 hours and provide a tracking reference.
Scope
In scope ✓
- ✓aegisfirma.com and all subdomains
- ✓Aegis Firma web application (aegisfirma.com)
- ✓Aegis Firma API (all /api/* endpoints)
- ✓Aegis Firma browser extensions (Policy Checker, Disclosure Verifier, Contract Scanner, AI Tools Scanner)
- ✓Authentication and session management
- ✓Data access controls (cross-organization data leaks, privilege escalation)
- ✓Payment and subscription flows
Out of scope ✗
- ✗Denial of service attacks (DoS/DDoS)
- ✗Social engineering or phishing attacks against Aegis Firma staff
- ✗Physical attacks against infrastructure
- ✗Vulnerabilities in third-party services (Supabase, Cloudflare, LemonSqueezy) — report those directly to the vendor
- ✗Automated scanner findings without proof of exploitability (reduce noise)
- ✗Missing security headers on non-application pages (marketing pages)
- ✗Self-XSS that requires the attacker to already control the account
- ✗Password complexity or account lockout policies that meet industry standards
Severity levels and response SLA
| Severity | Examples | Fix Target |
|---|---|---|
| 🔴 Critical | Remote code execution, auth bypass, full data exfiltration | 7 days |
| 🟠 High | Cross-org data access, privilege escalation, significant data exposure | 30 days |
| 🟡 Medium | XSS, CSRF, limited data exposure, session fixation | 60 days |
| 🟢 Low | Information disclosure, minor logic flaws, missing security headers | 90 days |
These are targets, not guarantees. We will always communicate timeline and progress updates.
Triage workflow
- New: Report received, tracking ID assigned.
- Acknowledged: Sent within 48h. Confirms we received your report.
- Validated: We reproduced the issue and confirmed it is a genuine vulnerability.
- In Progress: Fix underway. We may reach out for clarification.
- Fixed: Patch deployed. We verify the fix and notify you.
- Disclosed: Coordinated public disclosure (if you want to publish a write-up, we coordinate timing).
Rewards
We do not currently offer monetary bug bounties. We're an early-stage company. What we do offer:
Hall of Fame
Public acknowledgment on our Hall of Fame page for all validated reports.
Security Contributor Badge
A "Security Contributor" badge on your Aegis Firma account profile (if you have one).
Reference letter
A signed reference letter from the founder for Critical/High severity findings.
When revenue allows (post-Series A), we plan to introduce monetary rewards. Early contributors will be remembered.
Our commitments to you
- ✓We will not pursue legal action against you for good-faith security research within this policy's scope.
- ✓We will not share your personal information with third parties without your explicit consent.
- ✓We will acknowledge your report within 48 hours.
- ✓We will keep you informed as we investigate and fix the issue.
- ✓We will credit you publicly on our Hall of Fame if you consent.
- ✓If you discover our data alongside a vulnerability, do not access more than necessary and delete it immediately after reporting.
Coordinated disclosure
We follow a 90-day coordinated disclosure timeline as standard. This means:
- •You agree not to publish details of the vulnerability for 90 days from your report date.
- •If we fix the issue before 90 days, we will notify you and you can publish immediately (with our coordination).
- •For Critical vulnerabilities, we may request an embargo extension beyond 90 days only for issues where the fix requires significant infrastructure changes. We will explain why.
- •We will ship the fix before any public advisory is published.
If we discover a third-party library vulnerability while investigating your report, we will coordinate disclosure with the library maintainers following standard CVE processes.
Ready to report?
We appreciate your effort to make Aegis Firma more secure.