Trust

Aegis Trust Center

This page consolidates the core trust references Google reviewers, security teams, and end users need to evaluate Aegis: security controls, privacy commitments, support responsiveness, and reproducible release evidence.

Security architecturePrivacy disclosuresReproducible release artifacts
Core Sections

Security References

Aegis documents runtime trust boundaries, sender validation, and lock policies for extension and API workflows.

  • Security architecture: /security-overview
  • Password hardening guide: /password-protection
  • Developer security model: /developer/security

Privacy and User Rights

Privacy commitments and support channels are publicly available for policy and legal review.

  • Privacy policy: /privacy
  • Support and escalation: /support
  • Terms and service boundaries: /terms-and-services

Compliance Artifacts

Security reviewers can access trust artifacts that map controls, evidence, and governance answers.

  • Compliance overview: /compliance
  • Compliance FAQ: /compliance/faq
  • Controls matrix: /compliance/controls-matrix

Release Integrity

Extension releases include deterministic integrity metadata, signed archives, and attestation artifacts.

  • SHA-256 archive checksums for store bundles.
  • Signature and attestation metadata for reproducible verification.
  • Reviewer instructions included with submission bundles.

Operational Accountability

Aegis maintains policy disclosures, launch QA evidence, and support workflows to improve approval confidence and incident readiness.

  • Permission rationale and data-usage disclosures are tracked per release.
  • E2E launch QA matrix is maintained for extension autofill/save paths.
  • Critical incident escalation channel and response targets are documented.