Vulnerability Disclosure Policy
Last Updated: September 10, 2026
Vulnerability Disclosure Policy
Aegis Cyber Defense is committed to maintaining the security, integrity, and availability of our systems, services, and website.
We recognize the valuable role played by security researchers, customers, and members of the cybersecurity community in helping identify potential security vulnerabilities. This Vulnerability Disclosure Policy outlines how to responsibly report security concerns and how we will respond.
If you believe you have discovered a security vulnerability involving Aegis Cyber Defense systems, services, or website assets, we encourage you to notify us promptly in accordance with this policy.
Our Commitment
When a vulnerability is reported in good faith, Aegis Cyber Defense will make reasonable efforts to:
Acknowledge receipt of the report.
Review and validate the reported issue.
Investigate identified vulnerabilities.
Take appropriate corrective action when warranted.
Maintain open communication regarding the status of the report.
Recognize and appreciate responsible disclosure efforts.
Scope
This policy applies to:
The Aegis Cyber Defense website
Public-facing web applications owned by Aegis Cyber Defense
Publicly accessible services operated by Aegis Cyber Defense
Systems and infrastructure under the direct control of Aegis Cyber Defense
Out of Scope
The following are generally considered outside the scope of this policy:
Third-party services not owned or controlled by Aegis Cyber Defense
Social engineering attacks against employees, contractors, clients, or partners
Physical security testing
Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) testing
Spam or phishing campaigns
Automated vulnerability scans that negatively impact service availability
Vulnerabilities requiring access to client-owned environments
Issues related solely to unsupported browsers or software
Responsible Disclosure Guidelines
When conducting security research involving systems owned by Aegis Cyber Defense, we ask that you:
Act in good faith.
Avoid privacy violations.
Avoid destruction or modification of data.
Avoid actions that would negatively affect service availability.
Limit testing to only what is necessary to verify a vulnerability exists.
Avoid accessing, downloading, or altering information that does not belong to you.
Immediately stop testing and notify us if sensitive data is exposed.
Please Do Not
We request that researchers do not:
Access data belonging to customers or third parties.
Modify or delete data.
Establish persistence within any system.
Use discovered vulnerabilities to pivot into additional systems.
Publicly disclose vulnerabilities before we have had a reasonable opportunity to investigate and address them.
Conduct testing that degrades performance, availability, or reliability.
How to Report a Vulnerability
Please provide the following information when submitting a report:
A detailed description of the vulnerability
The affected URL, system, application, or service
Steps to reproduce the issue
Potential impact of the vulnerability
Screenshots, logs, or supporting evidence, if available
Your contact information so we can follow up if necessary
Reports should be submitted to:
Email: michael@aegis-cyber-defense.com
Subject Line: Vulnerability Disclosure Report
What to Expect After Reporting
After receiving a vulnerability report, Aegis Cyber Defense will:
Review the information submitted.
Validate the reported issue where possible.
Determine the potential risk and impact.
Take appropriate remediation measures.
Communicate with the reporter as needed during the review process.
Please note that not all submitted issues will be determined to be security vulnerabilities.
Safe Harbor
Aegis Cyber Defense supports responsible security research conducted in good faith.
We will not pursue legal action against individuals who:
Follow this policy.
Act in good faith.
Avoid causing harm.
Respect privacy and data confidentiality.
Promptly report discovered vulnerabilities.
This Safe Harbor provision applies only to activities conducted in accordance with this policy and applicable law.
No Bug Bounty Program
At this time, Aegis Cyber Defense does not operate a paid bug bounty or vulnerability reward program.
While we greatly appreciate responsible vulnerability disclosures, submission of a report does not create an expectation of compensation.
Client Systems Excluded
This policy applies only to systems owned and operated by Aegis Cyber Defense.
Client environments, networks, applications, cloud tenants, endpoints, and infrastructure are strictly excluded from this policy and must not be tested without the explicit written authorization of the client.
Policy Updates
Aegis Cyber Defense reserves the right to update or modify this Vulnerability Disclosure Policy at any time.
Changes will become effective immediately upon publication of the revised policy on this website.
Contact Information
Aegis Cyber Defense
Mansfield, Texas
Phone: 817-828-4982
Email: michael@aegis-cyber-defense.com
Website: https://www.aegis-cyber-defense.com