Version 0.1-draftEffective date Not yet in forceApplies to aegispethub.co.uk
PLACEHOLDER — Draft structure only. Final wording requires solicitor / data-protection sign-off before launch (Scope of Work §8.4).
1. Our security commitments
The registry holds personal data that matters to pet keepers, so security is a core obligation, not an afterthought. At a high level, we commit to:
- Encrypting data in transit and at rest.
- Restricting access to personal data to those who need it, with role-based permissions and audit logging of access to records.
- Building and reviewing features with security in mind, and keeping our systems and dependencies patched.
- Choosing reputable suppliers and holding them to contractual security obligations.
- Maintaining an incident response process, including notifying the ICO and affected individuals where the law requires it.
We deliberately do not publish details of our architecture, technology versions or internal controls on this page, as doing so would assist attackers more than it would reassure users.
2. Reporting a vulnerability
If you believe you have found a security vulnerability in aegispethub.co.uk or a related Aegis service, please email security@aegispethub.co.uk with:
- A description of the issue and where you found it.
- Steps to reproduce it, or a proof of concept.
- Your assessment of the potential impact.
- How we can contact you for follow-up.
3. Responsible disclosure guidelines
- Do not access, modify or delete data belonging to others; use test accounts you control wherever possible.
- Do not run denial-of-service tests or degrade the service.
- Do not publicly disclose the issue before we have had a reasonable opportunity to fix it — we will agree a disclosure timeline with you.
- Never include real personal data from our systems in your report; describe it rather than copying it.
We will not pursue legal action over good-faith research that follows these guidelines.
4. What happens after you report
- We acknowledge your report within 3 working days.
- We investigate, keep you informed of progress, and tell you when the issue is resolved.
- With your agreement, we are happy to credit researchers who report valid issues responsibly. We do not currently operate a paid bug bounty programme.
5. Security contact
Security reports only: security@aegispethub.co.uk. For anything else — account problems, data rights, general questions — use support@aegispethub.co.uk so your message reaches the right team.