Security practices

How we protect your home file

You are handing us photographs of everything you own. This page states plainly how that is held, what we deliberately do not claim, and how to reach us if you find a weakness. Last updated August 11, 2026.

  • Encrypted vault
  • Database-enforced access control
  • Two-factor available
  • Leaked-password screening
  • Account activity trail
  • We never sell your data
  • 14-day money-back guarantee

What our badges mean

Two badges appear across the site. Both are our own statements, not a third-party seal, certification or audit result — here is exactly what each one commits us to.

These are Aegis' own self-attested badges — not a third-party seal or certification. Tap either one to read exactly what stands behind it.

Aegis Trusted Site
Documents and photos are encrypted at rest and in transit and served only through short-lived signed links, and ownership is checked by the database on every read and write — not by app code.
Customer Satisfaction Guaranteed
If Aegis isn't what you expected, email support@aegishome.life within 14 days of your first paid charge for a full refund. Cancel any time — your home file stays readable and exportable.

How your home file is stored

Inventory records, photographs, receipts, appraisals and policy documents are held in managed Postgres and encrypted object storage, encrypted at rest and in transit over TLS.

Vault files are never public. They are served only through short-lived signed links generated for your session, so a copied URL stops working shortly after it is issued.

Scan data is kept for as long as you choose — 30, 90 or 365 days — and discard-raw mode drops the original capture as soon as the parsed values are saved, so the item keeps its data and the raw image does not linger. The scan log records what changed and when, with provider internals masked.

Stored photographs and documents are fingerprinted with a content hash and a first-seen date, and you can re-verify any file later to demonstrate it existed before a loss and was not altered afterwards.

How access is enforced

Every row in the database carries an owner, and access rules are enforced by the database itself rather than by application code. A request that does not carry your session returns nothing at all.

There is no internal console for browsing customer inventories. Support can see account and billing metadata, not your rooms, values, photographs or documents.

Sharing with an adjuster is explicit and time-boxed: you create a link, it expires, and you can revoke it at any moment.

Share links are passcode-protected with a passcode you can generate in the app and pass on separately. After ten wrong passcodes a link pauses for fifteen minutes, so a leaked URL cannot be guessed open.

Account protection

You can turn on an authenticator-app (TOTP) second factor in Account settings, and sign out of every device at once from the same screen.

You can register a passkey — Face ID, Touch ID, Windows Hello or a security key — as a step-up unlock. Aegis asks for it before an adjuster link is issued or a claim packet is exported, and one confirmation covers the next 15 minutes.

On a device you control you can choose to be remembered for 30 days, so routine shares and exports do not re-ask every time. Remembered devices are listed in Account settings with the date they were trusted and last used, and forgetting one — or all of them — takes effect immediately.

When your account is opened on a device we have not seen before, we email you the device, time and network so an unexpected sign-in is visible within minutes.

Passwords are screened against known breach lists at sign-up and whenever you change them.

Sensitive actions — sign-ins, vault views, adjuster shares, exports and subscription changes — are recorded in an append-only account activity trail that you can read but not rewrite.

Vendors and data handling

We rely on a short list of infrastructure vendors, published in full on the subprocessor page, and we do not sell, rent or broker your data to anyone.

Payment card details are handled entirely by our payment processor. Aegis never sees or stores card numbers.

What we do not claim

Aegis does not hold a SOC 2, ISO 27001 or PCI audit report today, and we will not display a badge suggesting otherwise. We are working through the control set a SOC 2 audit tests — access reviews, audit logging, retention and vendor management — and will say so plainly when that changes.

No service can promise it will never be attacked. What we can promise is that the design limits what a single compromised session or account can reach, and that we will tell affected account holders promptly if customer data is ever exposed.

SOC 2 readiness

Aegis is working through the control set a SOC 2 audit tests — access reviews, audit logging, retention and vendor management — and ships the control areas below today. We do not hold a SOC 2, ISO 27001 or PCI audit report, and nothing here should be read as a certification, audit result or third-party attestation.

Security & Compliance Roadmap

The security controls that are shipped and running today.

  • Database Access Controls & Encryption

    Live

    Row-level access rules are enforced by the database itself, not by app code. Storage is encrypted at rest.

  • Zero-Knowledge Vault Option

    Live

    Receipts, appraisals and policy documents live in a private vault reachable only through short-lived signed links.

  • Two-Factor Authentication (Authenticator App)

    Live

    Optional TOTP second factor on every account, plus leaked-password screening at sign-up, an append-only account activity trail, and one-tap sign-out across devices.

  • SOC 2-Aligned Security Controls

    Live

    The control areas a SOC 2 audit tests are implemented today: database-enforced row-level access, an append-only account activity trail, two-factor authentication, documented retention and deletion windows, and a published subprocessor list. No audit report is claimed.

Zero-Knowledge Architecture

Your inventory and photo uploads are encrypted at rest and in transit. Access rules are enforced directly at the database level — a request without your session simply returns nothing.

  • Per-row ownership checks on every read and write
  • Vault files served through expiring signed links only
  • No shared admin browsing of customer inventories

What is implemented today, by SOC 2 trust service category

A plain-language restatement of shipped behavior — not an audit matrix.

Security
Database-enforced row-level access on every read and write, optional authenticator-app (TOTP) and passkey step-up, leaked-password screening at sign-up and password change, and an append-only account activity trail the account holder can read but not rewrite.
Availability
Vault files are served only through short-lived signed links, recovery and claim packets can be packaged for export across multiple properties, and a 30-day export window protects access before a closed account is permanently deleted.
Confidentiality
Inventory and uploads are encrypted at rest and in transit, Aegis does not sell, rent or broker customer data, and the full vendor list is published on the subprocessor page.

Retention windows for vault files, adjuster shares and audit entries are stated in the privacy policy. For the vendors involved, see the subprocessor list.

Reporting a vulnerability

If you believe you have found a security issue in Aegis, email support@aegishome.life with enough detail to reproduce it. We acknowledge reports within one business day and will keep you updated until the issue is closed.

  • Safe harbour. We will not pursue legal action against researchers who report in good faith, stay within their own test accounts, avoid privacy violations and data destruction, and give us reasonable time to fix the issue before disclosing it.
  • Out of scope. Denial-of-service testing, social engineering of our staff or customers, spam, and reports produced solely by automated scanners without a demonstrated impact.
  • No bounty yet. We do not run a paid bounty programme today. We do credit reporters who want to be named.
Email the security address

Paid plans carry a 14-day money-back guarantee — see the terms. For what we collect and how long we keep it, read the privacy policy; for the vendors involved, the subprocessor list. Operated by Daquan Group, LLC.