Security & compliance

Security is a requirement, not a feature.

Aegis handles professional and regulated data. Every technical decision is taken with this premise: our customers' clients' data must be treated as if it were our own.

Data residency

Data in the European Union.

Primary infrastructure is located in Germany (Frankfurt). No replicas outside the European Economic Area. Sub-processors disclosed on request.

Encryption

At-rest and in-transit.

At-rest encryption for database volumes and backups. All traffic over TLS 1.3. Application secrets stored in a dedicated vault.

Backup & continuity

Daily backups, 24h RPO.

Automated daily snapshots with 30-day retention. Target RTO 4 hours. Disaster recovery procedures tested periodically.

Access

Granular permissions, Row-Level Security.

Owner / admin / member roles, permissions assignable per module. Data access policies are enforced at the database level (PostgreSQL RLS), not only in the application.

Audit

Full traceability.

Every administrative action (invites, role changes, module activations, billing changes) is recorded in an audit log available to workspace admins.

GDPR

Compliant data processing.

Designation of controller and processor, register of processing activities, DPA available on request, handling of data subject requests.

Responsible disclosure

If you believe you've identified a vulnerability, please write to info@aegissystem.net with the technical details. We'll reply within 5 business days and keep you posted on the remediation process.