Developer transparency

Inspect what is public. Do not infer what is private.

Aegis publishes public integration contracts, schemas, examples, tests, documentation, release material, and security policy where intended to be public. Signed runtime artifacts are distributed separately under the Aegis release contract. The proprietary runtime core is not licensed as open source and remains governed by its applicable licenses and access controls.

01 / SOURCE

Public does not mean unrestricted.

Every public file remains subject to the license and terms that accompany that material.

02 / RELEASES

Artifacts have identities.

Version, manifest, signature, digest, and package boundaries are treated as security-relevant evidence.

03 / SECURITY

Report vulnerabilities privately.

Use the dedicated security channel instead of a public issue when a report could expose users or systems.

04 / CLAIMS

Shipping state stays explicit.

Public pages should describe capabilities that actually exist and keep planned work separate from shipped behavior.