Aegis · included with every site we host
Guarded properly.
Your website stands on other people’s code, and that code ages whether anyone is watching or not. Aegis watches. It updates your dependencies every week, automatically, and tells us the moment something needs a person instead.
What actually goes wrong
Almost nobody’s small-business website gets “hacked” in the way the word suggests. It rots, and something walks in through the gap.
No website is written from scratch. Yours is built on dozens of open-source packages, each maintained by someone else, each getting older from the day it ships. When a weakness is found in one, the maintainer publishes a fix, and publishes what the weakness was at the same time. That second part is the problem: from that moment on, the flaw is public knowledge, and every site still running the old version is a listed address.
Nobody targeted you. Software scans the whole internet looking for versions with known holes, because it’s cheap to do and it works. The window between a security patch existing and your site actually having it is the entire risk, and on an unmaintained site that window never closes.
The exposure window
← the day the flaw is made public
Same timeline, one tick per week.
What runs, every week, without asking
Three steps and a fork. Which side of the fork you land on is the only thing that ever involves a person.
Check
Aegis reads every dependency your site uses and compares it against what has been published since it last looked.
Update
Anything safe to move is moved, on a copy. Nothing has touched your live site yet.
Prove
The updated site is built and tested. This is the step that decides everything after it.
tests pass
It ships, and that’s it
The update goes live and nobody is told, because nothing happened worth telling anyone about. This is almost every week.
tests fail
Nothing ships. We’re told
The update is held rather than pushed through and hoped about, and raised with us, graded by urgency. A person enters here, and it is us, not you.
The quiet outcome is the one you pay for and never see. It is the reason this page is duller than it sounds.
When a person is needed
Nearly always because the new version breaks something that worked yesterday, not because anything is on fire.
An update that fixes a weakness sometimes also changes how the package behaves, and the site that worked on Monday stops working on Tuesday. Aegis will not ship that, so it holds the update and raises it. Someone then has to go in and make the site work with the new version, which is real work and takes real time.
How fast we get to it depends on how bad the underlying problem is, not on how much you pay.
Who pays for the fix
One rule, and one exception to it that only ever runs in your favour.
Anything red, we fix for free, on every tier. We host the site, Aegis found the hole, and billing you to close it would be charging for our own alarm going off. There is no version of this where a critical fix reaches an invoice.
Amber and below is the only thing that differs, and it differs on one axis: whether the work sits inside your hosting fee, or is quoted at £35/hr. It is scheduled at the same speed regardless.
| Severity | Core | Plus | Priority |
|---|---|---|---|
| Red · criticala hole to close | freethe current sprint | freethe current sprint | freethe current sprint |
| Amber and belowusually a breaking change | £35/hrnext sprint | includednext sprint | includedcurrent sprint |
New builds. A Foundry build comes with a one-year warranty: for the first 1 year after it’s finished, every Aegis fix is free, amber included, even on Core. It runs from build completion and then stops, after which the tiers above apply as normal. The warranty page has what's settled so far.
What Aegis is not
Security products are usually sold by implying they cover everything. Here is what this one genuinely doesn’t.
Four things Aegis does not protect you from, listed because a security product that only advertises its wins is hiding the shape of the gap.
- 01
It is not antivirus, and it is not a firewall.
Aegis closes the holes that come from ageing code. It does not inspect traffic or block attackers at the door.
- 02
It cannot save you from a weak password.
If someone signs in as you because the password was “password”, every dependency on the site can be perfectly current and it will not have helped.
- 03
It does not catch flaws in your own site’s code.
It watches the packages your site depends on. Mistakes in the code we wrote are ours to find, and we look for them separately.
- 04
It is not a guarantee.
A weakness nobody has discovered yet cannot be patched by anybody, us included. Aegis shortens the window; it cannot abolish it.
It handles the one that actually gets small businesses, and it handles it every week without being asked. That is a narrower claim than most of this industry makes, and it’s one we can keep.
It comes with the hosting
See the tiers.Aegis runs on every site on Styx, at every tier, and it’s already in the price. Questions about any of it: hello@page-flow.co.uk