Resources

Security and trust.

How Aetheron handles your data, what is in place today, and what is still on the roadmap.

In place today

  • Encryption

    AES-256 at rest, TLS 1.3 in transit.

  • Access control

    Role-based permissions down to the individual resource, not per-application.

  • Audit trails

    Immutable records of who acted, which agent ran, and what it changed.

  • Human authority

    Agents act within defined parameters, and consequential steps require sign-off.

Compliance

Aetheron is built for India's DPDPA 2023, and is HIPAA-ready for healthcare deployments. Data residency and processing terms are agreed per engagement.

SOC 2 is on the roadmap and Aetheron is NOT SOC 2 certified today. Any document claiming otherwise is not from us.

Reporting a vulnerability

If you have found a security issue, tell us before disclosing it publicly and we will work with you on a fix and a timeline. There is no monetary bounty programme yet; when one exists it will be published here with its scope and rules.

  • Email the details, including reproduction steps and affected endpoints
  • We acknowledge, investigate, and keep you informed through to the fix
  • We will credit you publicly if you want that, and stay quiet if you do not

Security question, or a finding to report?

Reach us directly. Security reports are read before anything else.

Contact us