Back to Home
Documentation
Privacy Policy
Effective Date: April 4, 2026Version: 1.0
What We Collect
Aegir collects security scan targets, CVE lookup results, AI-generated analysis reports, consent records, and the client IP address observed at consent time for audit integrity.
What Stays Local
- TShark packet capture files and capture metadata generated on your host.
- Scapy probe outputs used for firewall inference on your environment.
- Local network interface detection details used to bind capture interfaces.
- Nmap XML output and temporary parse artifacts produced during scan execution.
What Goes To Supabase
The backend stores scan metadata (such as scan mode, counts, and timestamps), redacted vulnerability summaries, AI summaries, and your consent audit trail for account history and compliance records.
Third-Party Data Flow
- CIRCL CVE API receives only product and vendor strings required for vulnerability enrichment. IP addresses and direct targets are not sent.
- Google Gemini receives redacted port and CVE context for advisory summarization. Direct scan targets, host identifiers, and raw packet capture data are excluded.
Your Rights
- Request access to your stored scan and consent records.
- Request deletion of your account-linked records where legally permissible.
- Revoke advanced-scan consent at any time from inside the desktop app.
Contact
A dedicated security contact channel will be published with the public release of Aegir.