AEGIS // Militaires Sans Frontières
LEGAL // PRIVACY
Aegis logo
Private security infrastructure

Privacy Policy

This policy explains what AEGIS processes, why the data is used, who may access it and how long it is retained inside the Militaires Sans Frontières security and investigation system.

Private system Effective 17 September 2026
01

Who operates AEGIS

AEGIS is operated by the administration of the private Militaires Sans Frontières Discord server.

It is used only for this server and is not offered as a public, multi-server or commercial service.

02

Why data is processed

AEGIS processes data for the following purposes:

  • verifying access to the private Discord server;
  • detecting VPNs, proxies, Tor, hosting networks and other suspicious connection signals;
  • identifying account correlations and possible alternate-account activity;
  • enforcing network blocks and verification overrides;
  • supporting moderation, incident response and internal investigations;
  • preserving relevant evidence while an investigation case is active;
  • maintaining an audit trail of sensitive administrative actions.

Automated network or account-correlation signals are treated as indicators, not as absolute proof that two accounts belong to the same person.

03

Discord account information

AEGIS may process Discord identifiers and profile information visible to the server, including user ID, username, display name, server nickname, account creation information, avatar, server avatar and banner information.

Discord OAuth is used during verification. AEGIS may request the identify and email OAuth scopes.

The raw email address returned by Discord is not stored. Only the boolean status indicating whether the Discord account has a verified email address may be retained.

04

Network and verification data

During verification, AEGIS may process:

  • public IP address;
  • ASN and network organisation/operator information;
  • connection classification such as fixed, mobile or hosting;
  • VPN, proxy, Tor, relay and datacenter indicators;
  • identified VPN provider information when reliably supplied by the network-intelligence provider;
  • country code and limited technical request information when useful for verification;
  • verification session history and decision reason codes;
  • a limited, non-invasive correlation fingerprint where enabled.

AEGIS does not use invasive browser fingerprinting techniques such as canvas, audio or exhaustive font fingerprinting.

05

Server activity and records

AEGIS is designed to maintain a security and investigation history of the private server.

This may include:

  • message content posted in the server;
  • message edits and previous versions;
  • messages later deleted by the author or moderators;
  • message author, channel, timestamps, replies and related metadata;
  • attachment metadata, MIME type, size and SHA-256 hash;
  • temporary copies of attachment files;
  • historical usernames, nicknames, avatars and banners;
  • moderation and investigation notes;
  • cases and evidence holds;
  • AEGIS administrative audit events.

Content deleted from Discord may therefore remain available inside AEGIS until its applicable retention period expires or an investigation hold is released.

06

Retention periods

AEGIS is intended to provide a substantial forensic history without acting as a permanent archive. The standard retention periods are:

Data category Standard retention
IP address, ASN and network intelligence 180 days
Messages, edits and deleted message content 180 days
Raw attachment files 7 days
Attachment metadata and SHA-256 hashes 180 days
Username, nickname, avatar and banner history While present + 180 days
Member records after leaving the server 180 days
AEGIS administrative audit events 365 days
Network blocks 90 days by default
Encrypted off-box backups 30 rolling days

Specific records linked to an active investigation case may be placed on hold and retained beyond their normal expiry date while the case remains open.

After a case is closed, held data may remain available for up to 30 additional days before the normal retention rules are applied.

07

Backups and restoration

Encrypted off-box backups may be retained for up to 30 rolling days.

If an older backup is restored, AEGIS retention and purge rules are re-applied before the restored service is considered operational so that expired data is not intentionally returned to active use.

08

Who can access sensitive data

Sensitive investigation information such as raw public IP addresses, detailed network history, account correlations, deleted message history and full member dossiers is restricted to specifically authorised AEGIS operators.

Ordinary Discord permissions such as Administrator or server ownership do not automatically grant access to AEGIS investigation data.

Sensitive administrative access and consultation events may themselves be recorded in the AEGIS audit trail.

09

Third-party services

AEGIS relies on a limited number of external services required for the verification flow.

  • Discord provides account identity and OAuth authentication.
  • Cloudflare Turnstile may be used to reduce automated abuse of the public verification page.
  • A network-intelligence provider may receive an IP address for the purpose of classifying VPN, proxy, hosting, ASN or connection-type signals.

These providers operate under their own privacy policies and may process technical data necessary to provide their services.

10

Security

AEGIS is operated on private infrastructure hosted in the European Union. Sensitive services are not exposed directly to the public network where this is not required.

Access controls, audit logging, restricted service credentials, encrypted backups and automatic retention jobs are used to reduce unauthorised access and uncontrolled data retention.

11

Your data and requests

Members may contact the server administration regarding personal data processed by AEGIS, including requests concerning access, correction, deletion or restriction where applicable.

A request may be refused or limited where retaining specific information is necessary for an active security or moderation investigation, or where another applicable obligation requires retention.

You may also contact the data-protection supervisory authority applicable to you if you believe your personal data has been handled unlawfully.

12

Changes to this policy

This policy may be updated when AEGIS, its providers, retention rules or server security practices change.

The version currently published on this page is the applicable version.

Read the Terms of Service