Aegis AI Guard

Trust and security

A clear summary of implemented controls and customer assurance paths. Aegis does not claim certifications or independent audits that have not been completed.

Tenant isolation

Organization-scoped authorization and PostgreSQL row-level security are tested as release gates. Privileged server operations use separate service credentials.

Prompt privacy

Hash-only event logging is the safer default. Plaintext retention is an explicit organization policy setting, with tenant-scoped retention and deletion controls.

Authentication

Supabase Auth provides email verification, recovery, and Google OAuth. Account access requires an active, accepted, non-deleted membership.

Operations

Release checks cover dependency scanning, migration validation, route contracts, browser smoke tests, monitoring, incident response, and backup readiness.

Security and procurement requests

Report vulnerabilities privately to aegisaiguard@gmail.com. Security questionnaires and a data processing addendum are available for review during a qualified customer evaluation. Their availability is not a claim of certification or regulatory approval.