Trust & security

A system that can act on your site must earn that trust.

Strict separation between customers, tightly limited access, minimal data collection and reversible action are requirements we must meet before release — not features we add later.

Capabilities

What this covers

The boundaries we hold ourselves to, before we ever touch your traffic.

In beta

Customers stay separate

Each customer's data and actions are isolated by design and checked with tests that try to break that boundary.

In beta

Every action is auditable

Who, why, on what evidence, how far and how to undo — recorded for every decision.

In beta

We collect as little as possible

Request contents, credentials and session tokens are not collected by default.

How it works

Three steps, start to finish

  1. 01

    Confirm ownership

    No scan or active control begins without proof that the site is yours.

  2. 02

    Limit authority

    Access and actions are scoped to a single customer and service.

  3. 03

    Prove rollback

    Our release checks include failure and recovery, not just the happy path.

FAQ

Questions, answered plainly

Are you a 24/7 security team?
No, and we won't claim to be. AegiFlow is a private beta with clearly stated support hours. We'd rather be honest about coverage than overpromise.
What data do you keep?
As little as possible. We avoid request bodies, credentials and session tokens by default, and we keep only bounded, purpose-specific evidence.

Review how we handle trust

Ask us the hard questions before you ever point a site at us.

Contact us