1. Purpose and scope
This policy states the security commitments [Legal Entity Name] makes in respect of the AegisOne platform, the agent software and the data processed through them. It applies to our personnel, contractors and systems.
2. Access control
Operator accounts are individual and invitation-based. Shared logins are prohibited. Access follows role rather than blanket administration, and privileged surfaces — the credential vault, remote sessions and audit records — are gated accordingly.
Multi-factor authentication using TOTP is available for operator accounts, and we recommend it be enforced for every account with administrative reach. Authentication endpoints are rate limited and login attempts are recorded.
Internal access to production is limited to personnel who require it, and is granted, reviewed and revoked as a deliberate action.
3. Agent and endpoint security
Endpoints enrol by presenting an install token with a configurable lifetime, issued deliberately from the console. The agent maintains an outbound connection to the platform and does not accept inbound connections, so enrolment does not require an inbound firewall rule on the endpoint.
Remote terminal sessions are authorised per session through a short-lived ticket, bound to the requesting operator identity, and written to the endpoint action log.
4. Data protection
Traffic between agents, browsers and the platform is carried over TLS. Data is organised by client, site and department, and access controls, reporting and deletion follow those boundaries.
Stored credentials are held in the vault and require an explicit reveal action, which is recorded in the audit log with the actor and target.
5. Logging and monitoring
Privileged actions are written to an append-only audit log capturing actor, action and target. Audit and authentication records are retained in line with tenancy retention settings and are exportable as evidence.
6. Vulnerability and patch management
We track vulnerabilities affecting our platform and dependencies, and remediate on a risk-prioritised basis. Reports from external researchers are handled under our Vulnerability Disclosure Policy.
7. Incident response
We maintain an incident response process covering detection, triage, containment, eradication, recovery and post-incident review. Where an incident affects customer personal data we will notify the affected customer without undue delay, with the facts available at the time and updates as the investigation proceeds.
8. Controls we do not currently have
Stating this explicitly is part of the policy, not an omission from it. As at the revision date we do not offer federated single sign-on (SAML or OIDC), passkey authentication, conditional access policies or IP allowlisting; and we hold no third-party certification, external audit report or published penetration test result.
Where a control you require is not listed above as implemented, please assume we do not have it and raise it with us during evaluation.
9. Review
This policy is reviewed at least annually and on any material change to the platform or its threat environment.