Breach Notification

How to report security breaches and how AegisGate Security, LLC notifies affected parties. Compliant with HIPAA, GDPR, and CCPA requirements.

Breach Notification Policy

Last updated: 2026-07-29 Policy owner: AegisGate Security, LLC Contact: security@aegisgatesecurity.io


Our Commitment

AegisGate Security, LLC is committed to transparency and timely notification in the event of a data breach. This policy describes:

  1. How to report a suspected breach to AegisGate
  2. How AegisGate notifies affected parties
  3. Our compliance with HIPAA, GDPR, and CCPA breach notification requirements

Reporting a Breach to AegisGate

Security Vulnerabilities

If you believe you have discovered a security vulnerability in any AegisGate product, please see our Vulnerability Disclosure Policy for reporting instructions.

Data Breaches

If you believe your personal data has been compromised through an AegisGate product or service, please contact us immediately:

ChannelDetails
Emailsecurity@aegisgatesecurity.io
PGPFingerprint: 97C0 418A DBE0 5396 (available in SECURITY.md)
Response time24-hour acknowledgment, 72-hour initial triage

AegisGate’s Breach Notification Commitments

HIPAA Breach Notification (45 C.F.R. § 164.400-414)

For Professional and Enterprise tier customers who have executed a Business Associate Agreement (BAA):

RequirementCommitment
Individual notificationWithout unreasonable delay, but no later than 60 days from discovery
HHS notificationAnnual log of breaches affecting fewer than 500 individuals; notification within 60 days for breaches affecting 500+ individuals
Media notificationIf a breach affects 500+ individuals in a single state or jurisdiction, notification to prominent media outlets in that state
ContentDescription of breach, types of information involved, steps individuals should take, contact information

GDPR Breach Notification (Article 33/34)

RequirementCommitment
Supervisory authorityNotification within 72 hours of becoming aware of a breach likely to result in a risk to data subjects’ rights
Data subjectsNotification without undue delay when breach is likely to result in a high risk to rights and freedoms
ContentNature of breach, categories and approximate number of data subjects, likely consequences, measures taken or proposed

CCPA/CPRA Breach Notification

RequirementCommitment
NotificationExpedited notification to affected California residents
ContentTypes of personal information compromised, general description of breach, steps taken
FormatWritten notification delivered to last known address or email

Breach Severity Classification

LevelDefinitionInternal ResponseExternal Notification
Critical (P1)Confirmed data exfiltration, PHI exposure, credential theft1 hourWithin 72 hours (GDPR) or 60 days (HIPAA)
High (P2)Confirmed unauthorized access, limited scope4 hoursWithin 72 hours (GDPR) or 60 days (HIPAA)
Medium (P3)Suspected compromise, investigation needed24 hoursIf confirmed, within required timelines
Low (P4)No data exposure, policy violation7 daysNot required unless confirmed

Notification Channels

To Customers

MethodWhen Used
EmailPrimary notification channel for all breaches
In-product bannerFor active breaches affecting platform users
Security advisoryPublished at /cve/ for AI-specific vulnerabilities
This websiteProminent notice on the homepage

To Regulators

RegulatorWhenHow
HHS OCRBreach affecting 500+ individualsHHS Breach Portal
State attorneys generalAs required by state breach notification lawsWritten notification
Supervisory authority (GDPR)Breach likely to result in risk to data subjectsVia lead supervisory authority
California AGBreach affecting California residentsWritten notification per CCPA

To the Public

ChannelWhen Used
This pageAll confirmed breaches
CVE-for-AI feedAI-specific vulnerabilities (/cve/)
X/Twitter@aegisgate
Mastodon@aegisgate@mastodon.social

Self-Hosted Deployments

Important: AegisGate Security Platform is self-hosted and on-premises by design. AegisGate does not host, process, or store customer data outside the customer’s own infrastructure.

For self-hosted deployments:

  • AegisGate is not a data processor for customer data — the customer controls their own infrastructure
  • AegisGate will notify customers of vulnerabilities in the AegisGate software that could lead to a breach
  • Customers are responsible for their own breach notification to their end users and regulators
  • AegisGate will provide assistance and guidance to customers experiencing a breach

Past Incidents

AegisGate publishes all security advisories at /cve/. Current advisories:

IDDateSeverityDescription
AEGIS-2026-00012026-07-28HIGH (7.5)Prompt injection via Markdown image alt-text

Contact

For breach-related inquiries:


AegisGate Security, LLC maintains this breach notification policy in compliance with HIPAA (45 C.F.R. § 164.400-414), GDPR (Articles 33-34), and CCPA/CPRA (Civil Code § 1798.82).