Security
Aetheria OS is one connected platform — booking, channel manager, PMS, team workspace and owner reporting. Here is exactly how we keep your data safe across all of it.
Encryption
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Database backups are encrypted and stored securely.
Access Controls
Role-based access control governs an Owner / Manager / Staff capability matrix — who can view financials, manage staff, approve requests, edit properties or manage channels — enforced on the server across every app in the suite, not just hidden in the UI. Multi-factor authentication (MFA) is available for all accounts and enforced for admin roles.
Data Minimisation & Session Gating
Staff accounts start locked down and PDP-Law-aligned — guest data, channels and settings off by default, with owners switching on only what a specific role needs, per property. Every live surface (PMS, owner portal, team workspace, channel manager) requires an authenticated session; a missing or expired session degrades to a sign-in gate rather than exposing arrivals, guest data or payouts, and privileged checks fail closed.
Audit Logging
Sensitive and privileged actions are logged with timestamps, user identity, and IP address. Audit logs are tamper-evident and retained per our data-retention policy.
Infrastructure
Hosted on enterprise-grade cloud infrastructure with automatic failover, DDoS protection, and network-level firewalls. We maintain isolated environments for production and staging, and every host's data sits inside its own tenant boundary — never commingled across brands, even though each host runs their guest-facing booking, workspace and owner reporting under their own brand and logo.
Vulnerability Management
We run automated dependency scanning (CodeQL and scheduled audits) and code reviews, and patch critical vulnerabilities promptly.
Compliance
Our practices are aligned with GDPR, Indonesia's Personal Data Protection Law (UU PDP), and PCI DSS. Payment card data is handled by PCI-compliant processors (Xendit, Stripe). We support data processing agreements (DPAs) for enterprise customers.
Responsible Disclosure
If you discover a security vulnerability in the Aetheria OS platform, please report it responsibly by emailing security@aetheriaos.com. We will acknowledge receipt within 24 hours and work with you to understand and address the issue. We do not pursue legal action against good-faith security researchers.
Questions?
For security-related inquiries, contact our team at security@aetheriaos.com.