Legal

Security

A practical overview of how Aether protects customer data at aether.so.

Effective date: August 1, 2026

1. Overview

Aether is an AI social media agent used to connect social accounts, publish content, store media, run AI workflows, and capture campaign leads. Security is designed around least-privilege access inside companies and workspaces, encrypted credentials, and trusted service providers. Report security issues to security@aether.so.

2. Authentication & access control

  • Customer sign-in is handled through our authentication provider with secure session management.
  • Access inside the product is scoped by company and workspace, with membership roles (owner, admin, member) and permission checks on sensitive actions.
  • Device and session metadata (including hashed IPs where collected) helps manage active sessions.
  • Platform administration is separated from ordinary customer workspace roles.

3. Social connections

Social networks are connected through authorized account linking (OAuth or equivalent). Aether does not store social network passwords. Access credentials are encrypted at rest before storage.

Supported platforms: Instagram, X, Facebook, LinkedIn, Threads, TikTok, Telegram, and Reddit. You can disconnect accounts from the dashboard; revoked access stops API calls on our side once disconnection completes.

4. Encryption in transit & at rest

  • Public endpoints are served over HTTPS/TLS.
  • Social credentials are encrypted at rest.
  • Media and uploaded files are stored in secured cloud storage with access mediated by the Service.
  • Application data is hosted with industry-standard cloud database and infrastructure providers.

5. AI processing

AI features use third-party model providers to generate drafts, reports, and related outputs. Avoid submitting secrets into prompts that are not required for the task. Review AI output before publishing.

6. Customer data categories we protect

  • Account identity and workspace membership
  • Encrypted social credentials and connected-account metadata
  • Posts, media, inbox content, knowledge, and competitor reports
  • Tracking clicks/sessions (including hashed IPs) and CRM lead fields
  • Billing identifiers and subscription status

See the Privacy Policy for full collection and sharing details.

7. Payments

Subscriptions are processed by our payment provider. Card data is handled by that provider; Aether stores only the billing references needed for entitlements and history, not raw card numbers.

8. Application & operational controls

  • Authenticated access required for tenant data
  • Permission checks on sensitive actions (billing, publishing, team, etc.)
  • Abuse protections such as rate limiting on public surfaces
  • Verified payment webhook handling where configured
  • Protections against common OAuth connect abuses

9. Vulnerability reporting

If you believe you have found a security vulnerability in Aether, email security@aether.so with steps to reproduce. Please avoid public disclosure until we have had a reasonable chance to investigate and remediate. We will acknowledge legitimate reports and work to fix confirmed issues.

10. Shared responsibility

Security is shared: customers should use strong account authentication, limit workspace invites, review AI output, manage lead webhooks carefully, and follow each social platform’s security guidance. Hosting providers and social networks operate their own controls outside Aether’s perimeter.

© 2026 Aether (aether.so). For questions: legal@aether.so.