Account and session controls
Dashboard access is authenticated. Users can manage credentials, recovery and active account security from the private Security Center.
Aetherion AI
Operating Workspace
See how Aetherion protects account access, project data, server-only variables, generated previews and the external read-only API.
Identity
Authenticated
Workspace
Owner checked
Secrets
Encrypted
External API
Read only
Security is a continuing product process. This page documents the current boundary without claiming controls that have not been independently verified.
Dashboard access is authenticated. Users can manage credentials, recovery and active account security from the private Security Center.
Protected project operations verify the authenticated user and the project relationship before returning or changing workspace data.
Server-only project variables are encrypted with authenticated encryption, remain masked in the UI and are excluded from static project exports.
Generated applications run in a preview environment separated from the main Aetherion interface and privileged server credentials.
External API v1 exposes GET resources only. Every request rechecks the active paid plan and ownership of the requested project.
Aetherion API keys are stored as one-way hashes, shown in full only once and can be revoked from the user workspace.
External applications can inspect their own workspace data without receiving permission to create, edit, publish or delete projects.
Review API access120 requests per minute per API key
Request identifiers and consistent JSON errors
Pagination, filtering and explicit response fields
No .env, credentials, tokens or private keys in file responses
Paid-plan validation on every external request
Project-owner validation before project resources are returned
Scope and maturity
Authentication, project-level access checks, encrypted server variables, preview separation and read-only API controls are present in the current product.
More granular team roles, connector scopes, audit visibility and formal enterprise administration will expand with the multi-user operating layer.
Aetherion does not present this page as evidence of ISO 27001, SOC 2 or another independent certification unless that certification is explicitly published here.
Do not publish sensitive details. Sign in to create a protected security request, or email Aetherion Labs if account access is unavailable.