Security & compliance
Security is a requirement, not a feature.
Aegis handles professional and regulated data. Every technical decision is taken with this premise: our customers' clients' data must be treated as if it were our own.
Data residency
Data in the European Union.
Primary infrastructure is located in Germany (Frankfurt). No replicas outside the European Economic Area. Sub-processors disclosed on request.
Encryption
At-rest and in-transit.
At-rest encryption for database volumes and backups. All traffic over TLS 1.3. Application secrets stored in a dedicated vault.
Backup & continuity
Daily backups, 24h RPO.
Automated daily snapshots with 30-day retention. Target RTO 4 hours. Disaster recovery procedures tested periodically.
Access
Granular permissions, Row-Level Security.
Owner / admin / member roles, permissions assignable per module. Data access policies are enforced at the database level (PostgreSQL RLS), not only in the application.
Audit
Full traceability.
Every administrative action (invites, role changes, module activations, billing changes) is recorded in an audit log available to workspace admins.
GDPR
Compliant data processing.
Designation of controller and processor, register of processing activities, DPA available on request, handling of data subject requests.
Responsible disclosure
If you believe you've identified a vulnerability, please write to info@aegissystem.net with the technical details. We'll reply within 5 business days and keep you posted on the remediation process.