Security and trust

We hold ourselves to what we sell.

A security vendor asking for access to your website should be able to show how it protects itself. Here is how we run, in plain terms, including the parts that are not finished.

Operational viewIllustrative flow. No customer data.
What the current evidence supports

A state is shown as verified only while its evidence is recent. When a check has not run lately, the interface says Unknown instead of staying green.

01

What you can see and control

Every capability has a narrow responsibility, an operational state and evidence that explains the result.

01

Sign-in built for the job

Passkeys and one-time codes, sessions that live on our server rather than in your browser, and a second check before anything sensitive.

Available
02

Releases that can be undone

Every deployment records its source, its checksums and the exact command to go back — and the way back is rehearsed.

Available
03

Your data stays yours

Separation between customers is enforced by the database itself. Request contents, addresses and personal data are not collected for analysis.

Available
02

How you use it in an operating workflow

The visitor path remains short. Configuration, verification and rollback stay visible to the operator at every stage.

Fast request pathAnalyse en parallèleEvidence before promotion
  1. 01

    Ask us anything

    The security contact and reporting channel are published, not hidden behind a form.

  2. 02

    Check the states

    Each capability shows what is available, what is only being watched and what is not built yet.

  3. 03

    Hold us to it

    If a state is green without recent evidence, that is a bug — tell us.

03

The interface explains what is known, unknown and required

AegiFlow does not turn missing evidence into a reassuring zero. Every state links to its source, freshness and next action.

State
Available, observation, configuration required, degraded, unavailable or planned.
Evidence
Source, timestamp, scope and last successful verification.
Action
The responsible party, exact change and expected impact.
Way back
Rollback instructions are defined before an active change.
04

In depth

How this capability behaves in production — grounded in the platform's documented, current operation.

We hold ourselves to the standard we sell

Self-hosted identity with passkeys and step-up verification, opaque server-side sessions, immutable releases with checksums and rehearsed rollbacks, encrypted off-site backups with monthly restore drills, and a public security.txt with a real disclosure channel. The Trust Center shows capability states with the same honesty the dashboard shows customers.

Start in observation. Activate only measured controls.

Ownership, certificate, origin health and rollback must pass before traffic protection changes.

Open the Trust Center