Legal Document

Security Policy

September 3, 2026

Information security is part of AEGRIX's design, operations and service delivery. This policy summarizes general controls applied to the website and the responsible vulnerability disclosure process.


1. Responsible Party and Contact

Aníbal Benjamín Pérez Maestre · CEO of AEGRIX
Brand: AEGRIX
Tax identification (RUT): 700347984-1
Calle 30 88B, Belén, Medellín, Antioquia, Colombia
Email: contacto@aegrix.com.co

2. Scope

This policy applies to https://aegrix.com.co, its forms, official channels and digital services directly administered by AEGRIX.

3. Principles

AEGRIX applies confidentiality, integrity, availability, least privilege, defense in depth, data minimization, traceability, continuous updates and shared responsibility.

4. Website Controls

  • Server-side validation and request size limits.
  • Content escaping and header-injection controls.
  • Request-origin and context validation.
  • BotID, honeypot and rate limiting.
  • CSP, HSTS and browser protection headers.
  • No-store contact API responses.
  • Automated dependency audit, lint and build checks in CI.
  • Error logging designed not to expose full personal-data payloads.

5. Contact Form

The form validates input, separates required processing consent from optional marketing consent, applies abuse controls and does not return a false success in production when the email provider is unavailable.

6. Browser and Transport Security

The site uses HTTPS and controls including Content-Security-Policy, Strict-Transport-Security, anti-framing protections, Referrer-Policy, Permissions-Policy and cross-origin isolation headers.

7. Dependencies and Deployment

Changes pass through automated dependency installation, production vulnerability audit, lint and build checks before being considered valid.

8. Cybersecurity and AEGRIX 360

Assessment, readiness and assurance services are limited to the contracted scope. NIST, ISO/IEC 27001/27002, HIPAA Security Rule and GDPR may be used when relevant without presenting an assessment as certification or an absolute compliance guarantee.

9. Access Management

Client-system access should follow least privilege, exist only as long as necessary and be revoked or rotated when work ends where applicable.

10. Providers

The site relies on providers such as Vercel and Resend and may use Google Analytics after consent. AEGRIX manages its own configurations and minimizes shared information while providers remain responsible for their infrastructure.

11. Incidents

Relevant incidents are evaluated according to impact, affected information and applicable contractual or legal duties.

12. Responsible Vulnerability Disclosure

Security issues may be reported to contacto@aegrix.com.co with subject [SECURITY]. Reports should include the affected URL or asset, description, minimal reproduction steps, estimated impact and non-sensitive technical evidence.

13. Responsible Research Rules

  • Do not access, download, modify or disclose third-party data.
  • No denial of service, spam, social engineering, malware or destructive testing.
  • Do not persist access or escalate privileges beyond what is minimally required to document the issue.
  • Stop testing if personal/confidential information or availability risk appears.
  • Do not publish details before allowing a reasonable review and remediation opportunity.

14. Authorization Scope

This policy is not a general penetration-testing authorization. Only minimal, non-destructive, good-faith validation of a potential finding on public AEGRIX-managed assets is permitted. Deeper testing requires prior written authorization.

15. Privacy

Security reports are used to analyze and remediate findings. Please avoid including credentials, client data or unnecessary personal information.

16. Continuity

Backup, recovery and availability obligations for client projects are defined by contract. The corporate website does not claim absolute availability.

17. Updates

This policy may be updated as architecture, providers, controls or applicable obligations change.

Trust & Security

If you have questions about our legal documents, contact us at contacto@aegrix.com.co.