Legal Document

Security Policy

May 5, 2026

At AEGRIX, information security, digital asset protection, data confidentiality, and responsible management of technological risks are fundamental principles in our service delivery.

This Security Policy describes the general guidelines AEGRIX adopts to protect its website, digital channels, and information received from users and clients in relation to our software engineering, cybersecurity, AI, and consulting services.

This policy should be read alongside AEGRIX's Privacy Policy, Cookies Policy, and Terms and Conditions.


1. Scope

This policy applies to https://aegrix.com.co, official digital channels, contact forms, commercial communications, and all digital interactions related to AEGRIX.

2. Security Principles

AEGRIX guides its security management under the principles of Confidentiality, Integrity, Availability, Least Privilege, Necessity and Proportionality, Shared Responsibility, and Continuous Improvement.

3. Website Security

AEGRIX implements reasonable measures to protect its website from common risks like unauthorized access, form abuse, and malicious traffic. These include access controls, secure development practices, and regular updates.

4. Cybersecurity Services

Security services are executed according to the contracted scope. Clients acknowledge that no service can guarantee absolute protection or total risk elimination.

5. Client and User Responsibility

Users are responsible for providing truthful information, protecting their credentials, and timely implementing AEGRIX's security recommendations.

6. Permitted Use

Unauthorized access attempts, penetration testing without written consent, malware delivery, and unauthorized scraping are strictly prohibited.

7. Access Management

When client access is required, it is handled under confidentiality and least privilege. Clients must revoke access once the service is complete.

8. Information Confidentiality

Technical and commercial information is treated as confidential and will not be disclosed without authorization except by legal requirement.

9. Personal Data Protection

Personal information is treated according to our Privacy Policy and applicable Colombian regulations (Law 1581 of 2012).

10. Secure Development

Software projects apply secure development practices including environment separation, input validation, and secure dependency management.

11. AI and Data Security

Security and minimization criteria are applied to AI services. Clients must validate AI-generated results before critical use.

12. Third-Party Providers

AEGRIX uses reliable external providers but is not responsible for incidents exclusively attributable to these third parties.

13. Incident Notification

Relevant incidents will be managed based on impact and legal duties. Suspected incidents should be reported to contacto@aegrix.com.co.

14. Responsible Vulnerability Disclosure

Ethical reporting is valued. Vulnerability exploitation and access to third-party data are not authorized during reporting.

15. Backup and Conservation

Unless backup services are explicitly contracted, clients are responsible for maintaining updated copies of their critical information.

16. Continuity and Availability

AEGRIX strives for channel availability, though it may be affected by maintenance or external provider failures.

17. Limitation of Security Liability

Reasonable measures are implemented, but AEGRIX is not responsible for sophisticated attacks, third-party failures, or user negligence.

18. Legal Compliance

AEGRIX will cooperate with competent authorities when a legal obligation or formal requirement exists.

19. Policy Updates

This policy may be updated at any time by publishing it on the website.

20. Security Contact

Email: contacto@aegrix.com.co
Website: https://aegrix.com.co

Confianza y Seguridad

Si tienes alguna duda sobre nuestros documentos legales, puedes contactarnos en info@aegrix.com.co.