Information security is part of AEGRIX's design, operations and service delivery. This policy summarizes general controls applied to the website and the responsible vulnerability disclosure process.
Aníbal Benjamín Pérez Maestre · CEO of AEGRIX
Brand: AEGRIX
Tax identification (RUT): 700347984-1
Calle 30 88B, Belén, Medellín, Antioquia, Colombia
Email: contacto@aegrix.com.co
This policy applies to https://aegrix.com.co, its forms, official channels and digital services directly administered by AEGRIX.
AEGRIX applies confidentiality, integrity, availability, least privilege, defense in depth, data minimization, traceability, continuous updates and shared responsibility.
The form validates input, separates required processing consent from optional marketing consent, applies abuse controls and does not return a false success in production when the email provider is unavailable.
The site uses HTTPS and controls including Content-Security-Policy, Strict-Transport-Security, anti-framing protections, Referrer-Policy, Permissions-Policy and cross-origin isolation headers.
Changes pass through automated dependency installation, production vulnerability audit, lint and build checks before being considered valid.
Assessment, readiness and assurance services are limited to the contracted scope. NIST, ISO/IEC 27001/27002, HIPAA Security Rule and GDPR may be used when relevant without presenting an assessment as certification or an absolute compliance guarantee.
Client-system access should follow least privilege, exist only as long as necessary and be revoked or rotated when work ends where applicable.
The site relies on providers such as Vercel and Resend and may use Google Analytics after consent. AEGRIX manages its own configurations and minimizes shared information while providers remain responsible for their infrastructure.
Relevant incidents are evaluated according to impact, affected information and applicable contractual or legal duties.
Security issues may be reported to contacto@aegrix.com.co with subject [SECURITY]. Reports should include the affected URL or asset, description, minimal reproduction steps, estimated impact and non-sensitive technical evidence.
This policy is not a general penetration-testing authorization. Only minimal, non-destructive, good-faith validation of a potential finding on public AEGRIX-managed assets is permitted. Deeper testing requires prior written authorization.
Security reports are used to analyze and remediate findings. Please avoid including credentials, client data or unnecessary personal information.
Backup, recovery and availability obligations for client projects are defined by contract. The corporate website does not claim absolute availability.
This policy may be updated as architecture, providers, controls or applicable obligations change.
Trust & Security
If you have questions about our legal documents, contact us at contacto@aegrix.com.co.