Vulnerability Disclosure Policy
Last reviewed 2026-07-06Vulnerability Disclosure Policy
Our commitment
Aegix Global builds safety software for schools. Protecting the students, staff, and families who rely on it is our first priority, and security researchers help us do that. We welcome good-faith reports of vulnerabilities in our systems.
Scope
In scope: *.aegix.global and the Aegix web apps (AIM, SMS), the Aegix mobile apps
(iOS, Android), and their supporting public APIs.
Out of scope: third-party services we rely on (e.g. AWS, DuploCloud, Firebase); social engineering of Aegix staff, customers, or students; physical attacks; denial-of-service (DoS/DDoS) and volumetric testing; spam; and any testing that accesses, modifies, retains, or exfiltrates student data or other personal information.
Safe harbor
We consider security research conducted consistent with this policy to be authorized. If you make a good-faith effort to comply with this policy during your research, we will:
- not pursue or support legal action against you (including under the Computer Fraud and Abuse Act or DMCA § 1201) for accidental, good-faith violations of this policy;
- work with you to understand and resolve the issue promptly; and
- recognize your contribution if you are the first to report a valid, in-scope issue and we make a change based on it.
To stay within this authorization, you agree to:
- access only the minimum data necessary to demonstrate a vulnerability, and never access, store, or exfiltrate student records or personal data — FERPA-protected education records are strictly off-limits;
- stop testing and notify us immediately if you encounter any student or personal data;
- not degrade, disrupt, or destroy data or services;
- not exploit a finding beyond what is necessary to confirm it, and not pivot to other systems;
- give us reasonable time to remediate before any disclosure; and
- stay within the scope above and comply with applicable law.
If legal action is initiated by a third party against you for activities conducted consistent with this policy, we will take steps to make it known that your actions were authorized.
How to report
Email security@aegix.global — please encrypt sensitive details with our PGP key
(https://aegix.global/.well-known/pgp-key.txt). Include: the affected asset/URL, a description,
reproduction steps, and impact. Do not include real student or personal data in your report —
redact or describe it instead.
What to expect from us
- Acknowledgment within 3 business days.
- Validation and a triage severity, with status updates.
- Remediation targets: Critical 7 days / High 30 days (aligned to our internal SLAs).
- Coordinated disclosure: please allow 90 days before any public disclosure; we are happy to coordinate timing with you.
No bug bounty
This is a disclosure program. We do not currently offer monetary rewards.
Machine-readable pointer (security.txt)
The following is published at https://aegix.global/.well-known/security.txt (RFC 9116):
Contact: mailto:security@aegix.global
Expires: 2027-07-06T00:00:00.000Z
Policy: https://aegix.global/trust/vulnerability-disclosure
Preferred-Languages: en
Canonical: https://aegix.global/.well-known/security.txt
Publishing the security.txt file at the well-known path is handled in the website/trust-center
deploy (ADR-111) — a small follow-on to this policy landing.