Aegis · included with every site we host

Guarded properly.

Your website stands on other people’s code, and that code ages whether anyone is watching or not. Aegis watches. It updates your dependencies every week, automatically, and tells us the moment something needs a person instead.

What actually goes wrong

Almost nobody’s small-business website gets “hacked” in the way the word suggests. It rots, and something walks in through the gap.

No website is written from scratch. Yours is built on dozens of open-source packages, each maintained by someone else, each getting older from the day it ships. When a weakness is found in one, the maintainer publishes a fix, and publishes what the weakness was at the same time. That second part is the problem: from that moment on, the flaw is public knowledge, and every site still running the old version is a listed address.

Nobody targeted you. Software scans the whole internet looking for versions with known holes, because it’s cheap to do and it works. The window between a security patch existing and your site actually having it is the entire risk, and on an unmaintained site that window never closes.

The exposure window

← the day the flaw is made public

Unmaintained
open, and staying open
On Aegis
closed

Same timeline, one tick per week.

What runs, every week, without asking

Three steps and a fork. Which side of the fork you land on is the only thing that ever involves a person.

02

Update

Anything safe to move is moved, on a copy. Nothing has touched your live site yet.

03

Prove

The updated site is built and tested. This is the step that decides everything after it.

tests pass

It ships, and that’s it

The update goes live and nobody is told, because nothing happened worth telling anyone about. This is almost every week.

tests fail

Nothing ships. We’re told

The update is held rather than pushed through and hoped about, and raised with us, graded by urgency. A person enters here, and it is us, not you.

The quiet outcome is the one you pay for and never see. It is the reason this page is duller than it sounds.

When a person is needed

Nearly always because the new version breaks something that worked yesterday, not because anything is on fire.

An update that fixes a weakness sometimes also changes how the package behaves, and the site that worked on Monday stops working on Tuesday. Aegis will not ship that, so it holds the update and raises it. Someone then has to go in and make the site work with the new version, which is real work and takes real time.

How fast we get to it depends on how bad the underlying problem is, not on how much you pay.

Who pays for the fix

One rule, and one exception to it that only ever runs in your favour.

Anything red, we fix for free, on every tier. We host the site, Aegis found the hole, and billing you to close it would be charging for our own alarm going off. There is no version of this where a critical fix reaches an invoice.

Amber and below is the only thing that differs, and it differs on one axis: whether the work sits inside your hosting fee, or is quoted at £35/hr. It is scheduled at the same speed regardless.

What each Aegis severity costs, and when it is scheduled, on each Styx tier
SeverityCorePlusPriority
Red · criticala hole to closefreethe current sprintfreethe current sprintfreethe current sprint
Amber and belowusually a breaking change£35/hrnext sprintincludednext sprintincludedcurrent sprint

New builds. A Foundry build comes with a one-year warranty: for the first 1 year after it’s finished, every Aegis fix is free, amber included, even on Core. It runs from build completion and then stops, after which the tiers above apply as normal. The warranty page has what's settled so far.

What Aegis is not

Security products are usually sold by implying they cover everything. Here is what this one genuinely doesn’t.

Four things Aegis does not protect you from, listed because a security product that only advertises its wins is hiding the shape of the gap.

  1. 01

    It is not antivirus, and it is not a firewall.

    Aegis closes the holes that come from ageing code. It does not inspect traffic or block attackers at the door.

  2. 02

    It cannot save you from a weak password.

    If someone signs in as you because the password was “password”, every dependency on the site can be perfectly current and it will not have helped.

  3. 03

    It does not catch flaws in your own site’s code.

    It watches the packages your site depends on. Mistakes in the code we wrote are ours to find, and we look for them separately.

  4. 04

    It is not a guarantee.

    A weakness nobody has discovered yet cannot be patched by anybody, us included. Aegis shortens the window; it cannot abolish it.

It handles the one that actually gets small businesses, and it handles it every week without being asked. That is a narrower claim than most of this industry makes, and it’s one we can keep.

It comes with the hosting

See the tiers.

Aegis runs on every site on Styx, at every tier, and it’s already in the price. Questions about any of it: hello@page-flow.co.uk