Securing the agentic AI software supply chain

Security

Responsible disclosure and how we protect your data

Security is the product at Aephix, and we hold our own surface to the same standard. This page describes how we protect your data and how to report a security issue to us.

How we protect your data

  • All traffic is served over HTTPS and protected by HSTS, with a strict Content Security Policy and standard hardening headers.
  • We collect as little personal information as possible. See our Privacy Policy.
  • We rely on reputable infrastructure and service providers and pass data to them only as needed to run the Site.

Compliance

SOC 2 is in progress. We will update this page as our compliance posture matures.

Responsible disclosure

We welcome reports from security researchers and will work with you in good faith.

Scope. aephix.io, vantage.aephix.io, and the services we operate.

How to report. Email [email protected]. Our machine-readable policy is published at /.well-known/security.txt. Please include enough detail for us to reproduce the issue: the affected URL or component, the steps to trigger it, the impact, and any proof of concept.

Please. Give us a reasonable opportunity to remediate before any public disclosure. Do not access, modify, or delete data that is not yours. Do not degrade or disrupt our services, and do not run automated scans that generate significant traffic.

Safe harbor. If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research, and we will treat your activity as authorized.

What to expect. We will acknowledge your report, keep you updated as we investigate, and credit you if you wish once an issue is resolved.

Contact

Security issues: [email protected]. General questions: [email protected].