Aeterno is built to handle sensitive commercial and operational data, and we treat security as a product requirement, not an afterthought. This page describes our current approach at a high level. As we move customer data into the platform, we intend to formalize these practices under a recognized framework and will update this page and our access materials accordingly — any certification status referenced elsewhere on this site reflects where that process currently stands, not a claim of completion.
Connections to our website and product are encrypted in transit. Data we store is encrypted at rest using industry-standard encryption. We limit what we collect to what is necessary to operate the Site and, later, the product.
Access to systems that process customer or prospect data is restricted to personnel who need it to do their jobs, and is reviewed periodically. We use unique credentials and multi-factor authentication for internal systems wherever it is supported.
Where we rely on third-party infrastructure or service providers to operate the Site or product, we choose providers with their own strong security and compliance commitments, and we will publish a list of active subprocessors before onboarding customer data.
If you believe you've found a security vulnerability in our Site or product, please report it to security@aeterno.io before disclosing it publicly. Please include enough detail for us to reproduce the issue. We will acknowledge good-faith reports and will not pursue legal action against researchers who make a genuine effort to report issues responsibly and avoid privacy violations, data destruction and service disruption.
We maintain an internal process for investigating and responding to security incidents. Where a confirmed incident affects personal information, we will notify affected individuals and any required regulators in accordance with applicable law, including relevant U.S. state breach-notification statutes and Canada's PIPEDA breach-reporting requirements.
Security questions can be sent to security@aeterno.io. For privacy-specific requests, see our Privacy Policy.