Security
Security of the ÆTERION BRAIAN platform
Least privilege by default, encrypted data paths, isolated environments and a complete record of who did what, on which system.
Security of the ÆTERION BRAIAN platform
ÆTERION BRAIAN applies enterprise security controls to AI execution. Access is granted per role and per connector, never globally. Credentials live in the control plane and are never exposed to prompts. Data is encrypted in transit and at rest, environments are isolated, and every agent action is recorded with the policy version that authorised it.
Platform controls
- Single sign-on through your identity provider, with role-based access and enforced multi-factor authentication.
- Least-privilege connector permissions, scoped per process and per environment.
- Secrets stored encrypted in the control plane, rotated without touching process definitions.
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Separate development, staging and production environments with separate credentials.
- Append-only audit log of configuration changes, approvals and agent actions.
AI-specific risks we control
- Prompt injection
- Untrusted content is isolated from instruction context, and tool access is authorised by policy rather than by model output.
- Data leakage
- Redaction rules run before any request leaves the environment, and model routing can be restricted by jurisdiction.
- Over-permissioned agents
- An agent inherits only the permissions of the step it runs, for the duration of that step.
- Silent drift
- Model, prompt and policy versions are pinned and recorded, so behaviour change is attributable.
Operating practice
- Change management: configuration and releases pass a review and are reversible.
- Vulnerability management with dependency scanning and a defined patch window.
- Backups with tested restore procedures, and a documented business continuity plan.
- Independent penetration testing, with findings tracked to closure.
- Incident response with defined notification paths for customers.
FAQ
Where is the platform hosted?
In Switzerland or the European Union, or inside your own cloud tenancy. Hosting location is chosen at contract time and does not change silently.
Do you train models on our data?
No. Your data is not used to train models. Model providers are called under contractual terms that exclude training on submitted content.
Can we run a security review before signing?
Yes. We support security questionnaires, architecture reviews and, where required, a customer-run penetration test on a dedicated environment.
Send us your security review
We answer questionnaires and walk your security team through the architecture and controls.
