Skip to main content

Security

Aetheria OS is one connected platform — booking, channel manager, PMS, team workspace and owner reporting. Here is exactly how we keep your data safe across all of it.

Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Database backups are encrypted and stored in geographically redundant locations.

Access Controls

Role-based access control governs an Owner / Manager / Staff capability matrix — who can view financials, manage staff, approve requests, edit properties or manage channels — enforced on the server across every app in the suite, not just hidden in the UI. Multi-factor authentication (MFA) is available for all accounts and enforced for admin roles.

Data Minimisation & Session Gating

Staff accounts start locked down and PDP-Law-aligned — guest data, channels and settings off by default, with owners switching on only what a specific role needs, per property. Every live surface (PMS, owner portal, team workspace, channel manager) requires an authenticated session; a missing or expired session degrades to a sign-in gate rather than exposing arrivals, guest data or payouts, and privileged checks fail closed.

Audit Logging

Every action on the platform is logged with timestamps, user identity, and IP address. Audit logs are immutable and retained for a minimum of 12 months.

Infrastructure

Hosted on enterprise-grade cloud infrastructure with automatic failover, DDoS protection, and network-level firewalls. We maintain isolated environments for production and staging, and every host's data sits inside its own tenant boundary — never commingled across brands, even though each host runs the suite under their own brand and logo.

Vulnerability Management

We conduct regular penetration testing, automated dependency scanning, and code reviews. Critical vulnerabilities are patched within 24 hours of discovery.

Compliance

Our security practices are aligned with SOC 2, GDPR, Indonesia's Personal Data Protection Law (UU PDP), and PCI DSS practices; SOC 2 Type II audit in progress. Payment card data is handled by PCI-compliant processors (Xendit, Stripe). We support data processing agreements (DPAs) for enterprise customers.

Responsible Disclosure

If you discover a security vulnerability in the Aetheria OS platform, please report it responsibly by emailing security@aetheriaos.com. We will acknowledge receipt within 24 hours and work with you to understand and address the issue. We do not pursue legal action against good-faith security researchers.

Questions?

For security-related inquiries, contact our team at security@aetheriaos.com.