Aeterna AI Architects

Security

How a delivered Doc Generator instance is built to fail closed, not open.

API-key authentication on every endpoint

Every control endpoint — upload a template, fill variables, trigger a draft, retrieve results — requires an X-API-Key header validated server-side. No key configured means every request is rejected outright. There is no "open by default" fallback mode.

Encryption in transit

All traffic to and from a delivered instance runs over TLS. Template uploads, variable payloads, and generated documents are never transmitted in plaintext, including between the instance and the LLM provider you configure.

Your templates and documents stay yours

Your template library and generated documents live in the destination you configure — your storage, your CRM, your infrastructure. We don't retain a copy or route your documents through a third-party store we control.

Bring your own LLM key

The AI provider key the build uses is yours — OpenAI, Anthropic, or Gemini. You control the account, the spend cap, and can revoke access at any moment. We don't hold a standing copy of your keys after delivery; they are configured directly into your environment during handoff.

Optional scan recognition, isolated by design

OCR input is opt-in, off by default. A scan you upload is processed to extract structured text for the current draft only — it is not stored, cached, or reused beyond that single generation unless you explicitly configure a retention destination.

Credential handling during support

If a support task requires access to your environment, access is scoped to that specific task and time-boxed. We do not request or hold standing admin credentials to your infrastructure as a condition of delivery.

Incident response

If a security issue affecting a delivered build is identified — by us or reported to us — we will notify the affected party without undue delay, describe the exposure plainly, and ship a fix on a priority track, not the standard change-request queue.

Responsible disclosure

If you believe you've found a vulnerability in a delivered build or on this site, contact us through the channel you used to place your order, or through the general enquiry form. Describe the issue and, if possible, steps to reproduce it. We take reports seriously, do not pursue legal action against good-faith researchers who report responsibly and don't exfiltrate data beyond what's needed to demonstrate the issue, and will confirm receipt and a fix timeline directly.