Security · Responsible Disclosure

Vulnerability Disclosure Policy

Security researchers play a vital role in keeping AEGISLINK products safe. We welcome reports of potential security vulnerabilities and are committed to investigating and resolving them in good faith. This page explains how to report an issue, what's in scope, and what you can expect from us.

Last updated · Jun 18, 2026
Responsible disclosure

Report a vulnerability

Found a security issue in an AEGISLINK product, app, or service? Email our team directly and we'll take it from there.

Email our security team

We acknowledge every report within 5 business days. Please include the details listed below.

1 What to include in your report

The more detail you can share, the faster we can validate and fix the issue. Where possible, please include:

Affected product or service — model number, app version, or domain.
Firmware / software version — and hardware revision, if known.
A clear description of the vulnerability and its potential impact.
Steps to reproduce — proof-of-concept, scripts, or screenshots.
Your environment — network setup, region, or conditions required.
How to reach you — and whether you'd like to be credited.

2 Scope

This policy covers vulnerabilities in the products and services below. If you're unsure whether something is in scope, report it anyway and we'll let you know.

In scope

  • AEGISLINK connected devices and their firmware
  • The AEGISLINK Home mobile app (iOS & Android)
  • AEGISLINK cloud services and APIs
  • aegislink.com and official subdomains

Out of scope

  • Denial-of-service (DoS/DDoS) and volumetric attacks
  • Social engineering, phishing, or physical attacks on staff
  • Third-party services not operated by AEGISLINK
  • Reports from automated scanners without a demonstrated impact

3 Our commitment to researchers

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider it authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you. We ask that you:

  • Give us a reasonable opportunity to remediate before any public disclosure.
  • Only interact with accounts and devices you own or have explicit permission to test.
  • Avoid privacy violations, data destruction, and any disruption to our services.
  • Stop testing and notify us immediately if you encounter personal data.

4 What to expect from us

We follow a coordinated disclosure process. Our target response times:

1

Acknowledge within 5 business days

We confirm we've received your report and assign it a tracking reference.

2

Validate & triage within 10 business days

We reproduce the issue, assess severity and impact, and let you know our initial assessment.

3

Remediate target 90 days

We develop, test, and release a fix. We'll keep you updated on progress and expected timelines for complex issues.

4

Coordinated disclosure

Once a fix is available, we publish relevant details and, with your permission, credit your contribution.

5 Recognition

We're grateful to the researchers who help protect our users. With your consent, we're happy to acknowledge your contribution once an issue is resolved. If you'd prefer to remain anonymous, just let us know. AEGISLINK does not currently operate a paid bug bounty program; this is a coordinated disclosure program focused on recognition and a fast, collaborative fix.

To check the end-of-service date for a specific product, please visit: Product Service Summary .