Aether EO — Security

What Aether protects, and how.

Your Executive Operator is trusted with the working substance of your organization. These are the two questions that matter about it.

What Aether protects

Aether protects the information, decisions, actions, and organizational context entrusted to your Executive Operator.

  • Your organization's data
  • Executive and operational information
  • Customer and commercial records
  • Decisions and directives
  • Execution history
  • Organizational memory
  • Credentials and privileged actions
  • Separation from every other organization using Aether

The last one is not a feature of the list. It is the condition the rest of the list depends on.

How Aether protects it

Aether is built around enforced organizational boundaries, controlled authority, and traceable execution.

Organization isolation

Data is scoped to the organization it belongs to, with row-level access controls preventing one organization from accessing another's information.

Controlled access

Authentication alone does not grant unrestricted access. Permissions and authority are evaluated against the organization and the action being performed.

Protected execution

Sensitive actions run through governed server-side paths rather than exposing privileged credentials or unrestricted database access to the browser.

Least privilege

Anonymous and authenticated users receive only the access required for their role. Privileged functions and internal operating systems remain restricted.

Secure infrastructure

Aether runs on established cloud infrastructure through Vercel and Supabase, with encrypted HTTPS connections and managed production security controls.

Protected AI access

Model credentials remain server-side and are not accepted from client requests. Organizational data is not sent directly from the browser to the model provider.

Traceable actions

Aether records provenance, execution evidence, and receipts so important actions can be traced back to what happened, why it happened, and under what authority.

Governed external actions

Actions that affect systems outside Aether are separately authorized and recorded rather than being treated as ordinary internal operations.

Security boundaries are tested

Aether maintains behavioral tests around tenant separation, authentication, authority, privileged functions, provenance, and execution boundaries.

An Operator you can hand real work to is one whose boundaries hold when you are not watching.

See what it does

Aether EO runs on infrastructure provided by Vercel and Supabase. Those providers maintain their own security programs; their compliance status is theirs and is not a statement about Aether EO.