Aetherion AI

Operating Workspace

Aetherion trust center

Security begins witha clear access boundary.

See how Aetherion protects account access, project data, server-only variables, generated previews and the external read-only API.

Security boundary
Controls active

Identity

Authenticated

Workspace

Owner checked

Secrets

Encrypted

External API

Read only

Security is a continuing product process. This page documents the current boundary without claiming controls that have not been independently verified.

Identity · ownership · secrets · external access
Current controls

Protection across thewhole project lifecycle.

Account and session controls

Dashboard access is authenticated. Users can manage credentials, recovery and active account security from the private Security Center.

Project ownership checks

Protected project operations verify the authenticated user and the project relationship before returning or changing workspace data.

Encrypted project secrets

Server-only project variables are encrypted with authenticated encryption, remain masked in the UI and are excluded from static project exports.

Separated preview runtime

Generated applications run in a preview environment separated from the main Aetherion interface and privileged server credentials.

Read-only API boundary

External API v1 exposes GET resources only. Every request rechecks the active paid plan and ownership of the requested project.

Hashed API credentials

Aetherion API keys are stored as one-way hashes, shown in full only once and can be revoked from the user workspace.

API v1 is intentionally read-only.

External applications can inspect their own workspace data without receiving permission to create, edit, publish or delete projects.

Review API access

120 requests per minute per API key

Request identifiers and consistent JSON errors

Pagination, filtering and explicit response fields

No .env, credentials, tokens or private keys in file responses

Paid-plan validation on every external request

Project-owner validation before project resources are returned

Scope and maturity

What this page does—and does not—claim.

Implemented

Core product controls

Authentication, project-level access checks, encrypted server variables, preview separation and read-only API controls are present in the current product.

In development

Organisation controls

More granular team roles, connector scopes, audit visibility and formal enterprise administration will expand with the multi-user operating layer.

Not claimed

External certification

Aetherion does not present this page as evidence of ISO 27001, SOC 2 or another independent certification unless that certification is explicitly published here.

Found a vulnerability or suspicious account activity?

Do not publish sensitive details. Sign in to create a protected security request, or email Aetherion Labs if account access is unavailable.