Security
Last updated: July 1, 2026
1. Our approach
Security is a foundational requirement for Aethaar DevOp. Because our Agentic IDE interacts with your source code, we design our systems with a minimal attack surface, apply the principle of least privilege throughout, and continuously review our security architecture.
2. Infrastructure and Application Security
- Encryption: All data in transit is encrypted using modern TLS 1.2/1.3 standards. Sensitive data at rest is encrypted using AES-256 cryptographic protocols.
- Local Execution: We prioritize local models (e.g., Ollama) allowing you to execute code generation entirely offline without exposing your codebase to any external network.
- Access Control: Access to production systems is restricted to authorized personnel. API keys and credentials are never stored in source code and are managed securely.
- Dependency Scanning: We monitor our software dependencies for known vulnerabilities (CVEs) and issue updates rapidly.
- Session Security: Session tokens are managed securely and rotated automatically upon privilege changes.
3. Data Privacy Compliance
We are committed to operating in a manner consistent with global privacy frameworks:
- Formal Certifications: Aethaar's infrastructure aligns with SOC 2 Type II and ISO 27001 compliance frameworks, ensuring rigorous security controls.
- Data Retention: Telemetry, application logs, and support data are retained for a maximum of 90 days before permanent purging.
- GDPR & CCPA: We honor data subject rights requests (such as deletion and access requests) handled efficiently by our support team.
- Enterprise Isolation: Dedicated data residency and processing agreements are available for enterprise customers to ensure compliance with strict organizational requirements.
4. Vulnerability disclosure
We operate a responsible disclosure program. If you discover a security vulnerability in Aethaar DevOp or our website, we ask that you report it privately before public disclosure to give us time to address the issue.
Report vulnerabilities to: [email protected]
Please include a description of the vulnerability, steps to reproduce, and the potential impact. We will acknowledge receipt promptly and provide an estimated timeline for resolution. We do not currently offer a paid bug bounty program.
Legal Safe Harbor
We consider activities conducted consistently with this policy to constitute "authorized" conduct. Aethaar will not pursue civil action or initiate a complaint to law enforcement for accidental, good-faith violations of this policy, provided you do not intentionally compromise the privacy or safety of our users or systems.
5. Incident response
In the unlikely event of a confirmed security incident affecting customer data, we are committed to transparent communication. We will notify affected users promptly—consistent with applicable laws—detailing the nature of the incident, the data affected, and the mitigation steps we have taken.
6. Contact
Security questions, vulnerability reports, and general inquiries should be directed to our unified inbox at:
Email: [email protected]