Trust Center
What we do, what we don't, and how to reach us when something is wrong.
We use "aligned with", "designed for", and "maps to" deliberately, because a CISSP reads the difference between an alignment claim and a certification claim. This page states the difference explicitly.
What AegisGrid does
The runtime surface, honestly described.
These are capabilities AegisGrid provides in the deployed runtime. None of them are certifications; they are architectural commitments.
Local inference.
All reasoning runs on customer-operated hardware (Ollama or vLLM). No inference request leaves the host.
Hash-chained, signed audit log.
Every agent tool call, prompt, and decision is logged, signed, and replayable.
RBAC + break-glass admin.
Role-based access control scopes who can invoke workflows; a designated break-glass role holds the containment switch.
mTLS between agents.
All agent-to-agent and agent-to-tool traffic is mutually authenticated and encrypted in transit.
On-prem, air-gapped, or private cloud.
Three deployment topologies. Air-gapped is the most restrictive; private cloud is the most common.
What AegisGrid does NOT do
Explicit non-claims. Every one of these is binding.
We list these because the absence of the claim matters as much as the presence of the claim.
No SOC 2 Type II audit report yet.
AegisGrid does not currently hold a SOC 2 Type II audit report. NetWit parent is undergoing SOC 2 Type II audit; AegisGrid will inherit those controls when available.
No transmission of your data to commercial APIs.
There is no path by which your documents, alerts, or extracted controls reach OpenAI, Anthropic, Google, or any other commercial inference provider.
No training on your data.
We do not train models on customer artifacts. There is no shadow training corpus built from your vendor data.
No autonomous vendor approval decisions.
AegisGrid produces a draft risk matrix. The human analyst reviews, edits, and signs off. We never make a vendor go / no-go decision.
No retained document beyond the assessment record.
Documents are auto-deleted 30 days after the active assessment unless you request an extension. Configurable per engagement.
Data handling
Where your data lives, who can see it, and for how long.
TLS 1.3 in transit · AES-256 at rest · mTLS between agents.
On-prem or private-cloud deployment by default. Air-gapped topology available.
For Restricted data (e.g., Rutgers Policy 70.1.2 Restricted classification), zero third-party sub-processors; inference is local.
For non-Restricted data, the only sub-processors are the customer's own ServiceNow instance and SIEM (configurable). Customer is the data controller.
Retention default: 30 days for uploaded artifacts; 7 years for audit-log entries (configurable per customer compliance regime).
Uptime & reliability
Different deployment tiers, different commitments.
Public demo (aegisgrid.netwit.ca):
best-effort availability, no contractual SLA.
Enterprise on-prem deployments:
contractual SLA on inference availability and audit-log retention, negotiated per customer.
Private-cloud deployments:
contractual SLA on inference availability and audit-log retention, negotiated per customer.
Incident history
None to date.
No security incidents to date. If an incident occurs, it will be disclosed on this page within the timelines required by the customer's contractual SLA and applicable law (e.g., the 30-day FTC notification window under the GLBA Safeguards Rule for covered institutions).
Vulnerability disclosure
How to report a security issue.
Contact
Prefer the form? Use the contact form and mark the subject "Security disclosure".
Response SLAs
We acknowledge within 48 hours and aim to provide a remediation timeline within 7 days for confirmed vulnerabilities.
Encryption: please use our published PGP key (available on request from the contact form).
Scope
AegisGrid deployment components, the intake flow at aegisgrid.netwit.ca, and the audit-log surfaces. Third-party vendor issues (NetWit's other products) should be reported to the relevant product's disclosure channel.
Get in touch
Questions about a deployment, a clause, or a clause we don't list?
We'll route you to the right engineer. Disclosures go through the email above.