Aegis is pre-1.0 software. Security patches are only provided for the latest commit on the main branch.
Do not open a public issue. Please submit a private security advisory in the repository. Include the affected version, a minimal reproduction, potential impact, and any suggested mitigation. Avoid including real credentials or personal data.
We aim to acknowledge your report within 72 hours, validate the impact, and coordinate disclosure with you.
The current version of Aegis is for local development and evaluation only. It has not undergone an independent security audit and is not considered production-ready.
For detailed threat analysis, see our Threat model.