Aeterna AI Architects

Security

How a delivered Match Engine instance is built to fail closed, not open.

API-key authentication on every endpoint

Every control endpoint — register an entity, update criteria, trigger a match run, read results — requires an X-API-Key header validated server-side. No key configured means every request is rejected outright.

Encryption in transit

All traffic to and from a delivered instance runs over TLS. Entity payloads, criteria updates, and match results are never transmitted in plaintext.

Your data stays yours

Match results are delivered directly to the destination you configure — your webhook, your dashboard, your infrastructure. We don't retain a copy or route your data through a third-party store we control.

Bring your own credentials

Any delivery-integration keys the build uses (webhook secrets, CRM tokens) are yours. You control the account, the spend, and can revoke access at any time. We don't hold a standing copy after delivery.

Scoped matching, no silent data expansion

The engine only scores the two entity types and attributes explicitly configured at scoping. It does not enrich, cross-reference, or pull in external data sources beyond what you wired it to unless that was part of the agreed scope.

Credential handling during support

If a support task requires access to your environment, access is scoped to that specific task and time-boxed. We do not request or hold standing admin credentials as a condition of delivery.

Incident response

If a security issue affecting a delivered build is identified, we notify the affected party without undue delay, describe the exposure plainly, and ship a fix on a priority track.

Responsible disclosure

If you believe you've found a vulnerability in a delivered build or on this site, contact us through the channel you used to place your order. Describe the issue and, if possible, steps to reproduce it. We take reports seriously, do not pursue legal action against good-faith researchers who report responsibly, and will confirm receipt and a fix timeline directly.