Legal
Security
A practical overview of how Aether protects customer data at aether.so.
Effective date: August 1, 2026
1. Overview
Aether is an AI social media agent used to connect social accounts, publish content, store media, run AI workflows, and capture campaign leads. Security is designed around least-privilege access inside companies and workspaces, encrypted credentials, and trusted service providers. Report security issues to security@aether.so.
2. Authentication & access control
- Customer sign-in is handled through our authentication provider with secure session management.
- Access inside the product is scoped by company and workspace, with membership roles (owner, admin, member) and permission checks on sensitive actions.
- Device and session metadata (including hashed IPs where collected) helps manage active sessions.
- Platform administration is separated from ordinary customer workspace roles.
3. Social connections
Social networks are connected through authorized account linking (OAuth or equivalent). Aether does not store social network passwords. Access credentials are encrypted at rest before storage.
Supported platforms: Instagram, X, Facebook, LinkedIn, Threads, TikTok, Telegram, and Reddit. You can disconnect accounts from the dashboard; revoked access stops API calls on our side once disconnection completes.
4. Encryption in transit & at rest
- Public endpoints are served over HTTPS/TLS.
- Social credentials are encrypted at rest.
- Media and uploaded files are stored in secured cloud storage with access mediated by the Service.
- Application data is hosted with industry-standard cloud database and infrastructure providers.
5. AI processing
AI features use third-party model providers to generate drafts, reports, and related outputs. Avoid submitting secrets into prompts that are not required for the task. Review AI output before publishing.
6. Customer data categories we protect
- Account identity and workspace membership
- Encrypted social credentials and connected-account metadata
- Posts, media, inbox content, knowledge, and competitor reports
- Tracking clicks/sessions (including hashed IPs) and CRM lead fields
- Billing identifiers and subscription status
See the Privacy Policy for full collection and sharing details.
7. Payments
Subscriptions are processed by our payment provider. Card data is handled by that provider; Aether stores only the billing references needed for entitlements and history, not raw card numbers.
8. Application & operational controls
- Authenticated access required for tenant data
- Permission checks on sensitive actions (billing, publishing, team, etc.)
- Abuse protections such as rate limiting on public surfaces
- Verified payment webhook handling where configured
- Protections against common OAuth connect abuses
9. Vulnerability reporting
If you believe you have found a security vulnerability in Aether, email security@aether.so with steps to reproduce. Please avoid public disclosure until we have had a reasonable chance to investigate and remediate. We will acknowledge legitimate reports and work to fix confirmed issues.
10. Shared responsibility
Security is shared: customers should use strong account authentication, limit workspace invites, review AI output, manage lead webhooks carefully, and follow each social platform’s security guidance. Hosting providers and social networks operate their own controls outside Aether’s perimeter.
© 2026 Aether (aether.so). For questions: legal@aether.so.