Legal document

Security

Security practices and limitations for AethelLayer. Last updated: August 6, 2026.

Important legal notice: These documents are designed to protect AethelLayer and limit liability to the maximum extent permitted by law. They are not a substitute for advice from qualified legal counsel in your jurisdiction. Have an attorney review before relying on them for regulated industries, enterprise sales, or high-risk use cases.

1. Overview — no warranty

AethelLayer implements administrative, technical, and organizational measures designed to help protect information processed through our Services. THIS PAGE DESCRIBES OUR APPROACH AND YOUR RESPONSIBILITIES. IT DOES NOT CREATE ANY WARRANTY, SERVICE-LEVEL COMMITMENT, OR INSURANCE OBLIGATION BEYOND OUR TERMS & CONDITIONS.

Our public Trust & Security page at /security is informational marketing only and is not incorporated into contract unless referenced in a signed SOW.

Detailed security documentation for enterprise customers may be provided under NDA at our discretion upon written request to security@aethellayer.com. We may refuse requests from non-customers or competitors.

2. Infrastructure and isolation

NO ARCHITECTURE ELIMINATES ALL RISK. Shared cloud environments, third-party dependencies, and misconfiguration may result in incidents despite our efforts.

  • Cloud infrastructure with provider-dependent physical and environmental controls.
  • Encryption in transit via TLS 1.2+ for data over public networks where supported.
  • Encryption at rest for stored Customer Data using industry-standard algorithms (e.g., AES-256) where applicable to your tier.
  • Logical tenant isolation including separate workspace boundaries and access controls.
  • Network segmentation and least-privilege access for production systems operated by us.

3. Access control and authentication

  • Role-based access controls for platform administration.
  • Multi-factor authentication available or required for certain roles (deployment-dependent).
  • Session timeout and revocation capabilities where configured.
  • YOU are solely responsible for credential hygiene, SSO configuration, provisioning/deprovisioning users, and OAuth token scope minimization.

4. Monitoring and incident response

We maintain logging and monitoring and triage alerts by severity. We do not guarantee detection of all incidents.

We will notify you of a confirmed personal data breach affecting your Customer Data without undue delay where required by law, subject to law enforcement, forensic, or legal constraints. Notification does not admit fault or liability.

Report suspected vulnerabilities responsibly to security@aethellayer.com. UNAUTHORIZED TESTING, SCANNING, OR PROBING IS PROHIBITED AND MAY RESULT IN LEGAL ACTION.

5. Subprocessors

We use subprocessors for hosting, email, analytics, payments, AI, and support. A list is available upon request to paying customers.

You authorize subprocessors necessary to deliver the Services. We may change subprocessors with notice where required by your DPA or Terms. Objection rights, if any, are defined in your DPA or Terms — otherwise continued use constitutes acceptance.

6. Compliance posture — no certification warranty

We are preparing for SOC 2 Type II certification. UNTIL A REPORT IS ISSUED TO YOU UNDER NDA, NO CERTIFICATION, AUDIT, OR MARKETING CLAIM CONSTITUTES A WARRANTY OF SECURITY OR COMPLIANCE.

YOU ARE SOLELY RESPONSIBLE for determining whether our controls meet your regulatory obligations (GDPR, HIPAA, PCI, etc.) and for executing a DPA where required. Use of the Services without a DPA is at your risk.

7. Customer security obligations

  • Configure integrations with minimum necessary OAuth/API scopes; review grants quarterly.
  • Enforce MFA for administrators; prohibit shared credentials.
  • Do not upload malware, unlawful content, or unnecessary sensitive personal data.
  • Review AI and automation outputs before triggering payments, terminations, or external communications.
  • Maintain independent backups for business-critical data.
  • Notify us promptly of suspected compromise at security@aethellayer.com.

8. Security disclaimer and limitation

NO SECURITY MEASURE IS FOOLPROOF. YOU ACKNOWLEDGE INHERENT RISKS OF INTERNET TRANSMISSION AND CLOUD PROCESSING.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, WE DISCLAIM LIABILITY FOR UNAUTHORIZED ACCESS, DATA LOSS, CORRUPTION, OR BREACH CAUSED BY: (A) YOUR OR YOUR USERS' MISCONFIGURATION OR NEGLIGENCE; (B) THIRD-PARTY INTEGRATIONS OR PROVIDERS; (C) COMPROMISED CREDENTIALS ATTRIBUTABLE TO YOU; (D) SOCIAL ENGINEERING TARGETING YOUR ORGANIZATION; (E) ZERO-DAY OR NOVEL ATTACKS BEYOND REASONABLE INDUSTRY PRACTICE; OR (F) FORCE MAJEURE.

OUR LIABILITY FOR SECURITY INCIDENTS IS SUBJECT TO THE CAPS, EXCLUSIONS, AND INDEMNITIES IN OUR TERMS & CONDITIONS. SECURITY MEASURES DESCRIBED HERE ARE SUBJECT TO CHANGE WITHOUT NOTICE.

9. Contact

Security inquiries: security@aethellayer.com | Legal: legal@aethellayer.com