Aegisify company logo
Responsible Disclosure | Report Aegisify Security Issues Safely2026-07-28T02:38:43+00:00

Responsible Disclosure: Help Us Protect Aegisify Customers

Aegisify supports responsible security research that helps protect its products, customers, and WordPress environments. Potential vulnerabilities in Aegisify Audit, the Aegisify Agent, or any Aegisify plugin can be reported privately for safe investigation and coordinated remediation.

The disclosure process provides a clear path for authorized testing and confidential reporting while protecting customer data, service availability, and platform trust.

Aegisify Disclosure logo featuring a stylized shield icon and company name.

 

Responsible Security Disclosure

Aegisify welcomes responsible security research that helps us strengthen our WordPress products, SaaS platform, Agent connections, and customer data protections. If you believe you have discovered a security vulnerability, please report it privately so our team can investigate the issue and take appropriate action.

This disclosure process is intended for security researchers, WordPress professionals, developers, customers, and technology partners who identify a potential weakness in an Aegisify-owned product or service.

Security Issues We Want to Hear About

Please contact Aegisify when you discover a vulnerability that may affect the confidentiality, integrity, availability, authentication, authorization, or secure operation of an Aegisify product or service.

Examples of relevant security findings include:

  • Authentication or authorization bypasses
  • Cross-site scripting, SQL injection, request forgery, or insecure direct object reference vulnerabilities
  • Exposure of sensitive account, scan, telemetry, or security data
  • Weaknesses involving Agent authentication, domain connections, security keys, or telemetry access
  • Vulnerabilities affecting scan execution, report generation, dashboards, account boundaries, or SaaS workflows
  • Security issues involving WordPress audit results, plugin or theme intelligence, optional logs, code-analysis findings, externally observed evidence, or AI-assisted report data

Research Must Be Safe and Authorized

Security research should demonstrate the issue using the minimum access and activity needed to confirm that a vulnerability exists. Testing must remain limited to Aegisify systems you are authorized to evaluate and must not place customers, customer information, service availability, or third-party systems at risk.

Please do not:

  • Access, copy, download, modify, disclose, or delete customer data
  • Perform denial-of-service, high-volume load, spam, or destructive testing
  • Use phishing, social engineering, credential theft, or physical attacks
  • Install malware or establish persistent access to an Aegisify or customer environment
  • Test a customer’s WordPress website without the owner’s written authorization
  • Continue testing after sensitive information becomes visible
  • Publicly disclose an unresolved vulnerability before Aegisify has had a reasonable opportunity to investigate and respond

If you unexpectedly encounter customer information or other sensitive data, stop testing, do not retain or share the information, and notify Aegisify immediately.

How to Submit a Security Report

Send your report privately to support@aegisify.com with Security Report in the subject line.

A complete report helps our team reproduce, evaluate, and prioritize the issue. Please include:

  • The affected Aegisify product, feature, endpoint, or URL
  • A clear description of the suspected vulnerability
  • Safe and repeatable steps that demonstrate the issue
  • The potential security or business impact
  • Relevant product versions, browser details, WordPress versions, or environment information
  • Screenshots, request details, or redacted logs when they are necessary to explain the finding
  • Your preferred contact information for follow-up questions

Do not send passwords, live security keys, complete access tokens, payment information, or unredacted customer data with your report.

What Happens After a Report Is Submitted

Aegisify will review the information provided, evaluate whether the issue can be reproduced, assess its potential impact, and determine the appropriate response. We may contact the reporter for additional technical details or validation.

The time needed to investigate and address a report can vary based on its severity, technical complexity, affected products, required testing, and potential customer impact. We ask researchers to keep the report confidential while the investigation and remediation process is underway.

Good-Faith Security Research

Aegisify appreciates researchers who act in good faith, respect customer privacy, avoid service disruption, remain within authorized testing boundaries, and disclose findings privately through this process.

When research follows these requirements, Aegisify intends to work constructively with the reporter to understand the issue and improve the affected product or service. Activities involving unauthorized access, customer systems, privacy violations, data misuse, extortion, or destructive testing are not covered by this policy.

Bounties, Payments, and Recognition

Submitting a security report does not automatically qualify the reporter for a bounty, payment, reward, or public recognition. A reward is available only when Aegisify has an active written bounty program and the report satisfies that program’s eligibility requirements.

Responsible reports remain valuable even when no financial reward is offered. Recognition, when appropriate, will be discussed with the researcher and will not be published without permission.

Protecting Trust Across the Aegisify Platform

Aegisify brings together WordPress security audit findings, Agent telemetry, plugin and theme intelligence, code-analysis signals, externally observed evidence, optional logs, risk prioritization, and AI-assisted analysis. Protecting these workflows is essential to the customers, agencies, ecommerce operators, developers, executives, and security teams that rely on Aegisify.

Responsible disclosure gives qualified researchers a clear path to report potential weaknesses while protecting customer privacy, system availability, and the integrity of the investigation.

Understand the Security Posture of Your WordPress Site

Aegisify Audit helps WordPress professionals, marketing teams, executives, and security architects bring plugin and theme risk, code-analysis findings, external exposure, configuration posture, optional logs, and AI-assisted prioritization into one organized security workflow.

See what matters, understand the potential impact, and give your team a clearer path from technical evidence to informed action.

Start With Aegisify Audit
Explore Aegisify

All it takes is 30 minutes, you will love us!​​​​​​

14 days Free Trial. Cancel anytime with no pressure, no spam emails or phone calls.

Learn how Aegisify Audit works.

Understand the steps how Aegisify Audit connects its SaaS platform with a secure WordPress Agent to collect evidence, analyze risk, correlate findings, and turn complex scan data into clear, prioritized action.

A diagram illustrating the Aegisify service workflow process.
A person using a laptop to sign up for an account on a website.

Got Questions? We got Answers.

Still need answers, please contact us today!