AEGISGRID

Trust Center

What we do, what we don't, and how to reach us when something is wrong.

We use "aligned with", "designed for", and "maps to" deliberately, because a CISSP reads the difference between an alignment claim and a certification claim. This page states the difference explicitly.

What AegisGrid does

The runtime surface, honestly described.

These are capabilities AegisGrid provides in the deployed runtime. None of them are certifications; they are architectural commitments.

  • Local inference.

    All reasoning runs on customer-operated hardware (Ollama or vLLM). No inference request leaves the host.

  • Hash-chained, signed audit log.

    Every agent tool call, prompt, and decision is logged, signed, and replayable.

  • RBAC + break-glass admin.

    Role-based access control scopes who can invoke workflows; a designated break-glass role holds the containment switch.

  • mTLS between agents.

    All agent-to-agent and agent-to-tool traffic is mutually authenticated and encrypted in transit.

  • On-prem, air-gapped, or private cloud.

    Three deployment topologies. Air-gapped is the most restrictive; private cloud is the most common.

What AegisGrid does NOT do

Explicit non-claims. Every one of these is binding.

We list these because the absence of the claim matters as much as the presence of the claim.

  • No SOC 2 Type II audit report yet.

    AegisGrid does not currently hold a SOC 2 Type II audit report. NetWit parent is undergoing SOC 2 Type II audit; AegisGrid will inherit those controls when available.

  • No transmission of your data to commercial APIs.

    There is no path by which your documents, alerts, or extracted controls reach OpenAI, Anthropic, Google, or any other commercial inference provider.

  • No training on your data.

    We do not train models on customer artifacts. There is no shadow training corpus built from your vendor data.

  • No autonomous vendor approval decisions.

    AegisGrid produces a draft risk matrix. The human analyst reviews, edits, and signs off. We never make a vendor go / no-go decision.

  • No retained document beyond the assessment record.

    Documents are auto-deleted 30 days after the active assessment unless you request an extension. Configurable per engagement.

Data handling

Where your data lives, who can see it, and for how long.

  • TLS 1.3 in transit · AES-256 at rest · mTLS between agents.

  • On-prem or private-cloud deployment by default. Air-gapped topology available.

  • For Restricted data (e.g., Rutgers Policy 70.1.2 Restricted classification), zero third-party sub-processors; inference is local.

  • For non-Restricted data, the only sub-processors are the customer's own ServiceNow instance and SIEM (configurable). Customer is the data controller.

  • Retention default: 30 days for uploaded artifacts; 7 years for audit-log entries (configurable per customer compliance regime).

Uptime & reliability

Different deployment tiers, different commitments.

Public demo (aegisgrid.netwit.ca):

best-effort availability, no contractual SLA.

Enterprise on-prem deployments:

contractual SLA on inference availability and audit-log retention, negotiated per customer.

Private-cloud deployments:

contractual SLA on inference availability and audit-log retention, negotiated per customer.

Incident history

None to date.

No security incidents to date. If an incident occurs, it will be disclosed on this page within the timelines required by the customer's contractual SLA and applicable law (e.g., the 30-day FTC notification window under the GLBA Safeguards Rule for covered institutions).

Vulnerability disclosure

How to report a security issue.

Contact

security@aegisgrid.netwit.ca

Prefer the form? Use the contact form and mark the subject "Security disclosure".

Response SLAs

We acknowledge within 48 hours and aim to provide a remediation timeline within 7 days for confirmed vulnerabilities.

Encryption: please use our published PGP key (available on request from the contact form).

Scope

AegisGrid deployment components, the intake flow at aegisgrid.netwit.ca, and the audit-log surfaces. Third-party vendor issues (NetWit's other products) should be reported to the relevant product's disclosure channel.

Get in touch

Questions about a deployment, a clause, or a clause we don't list?

We'll route you to the right engineer. Disclosures go through the email above.