Encryption.
Encryption in transit and at rest by default, with bring-your-own-key and envelope encryption.
Encryption everywhere by default — TLS in transit and authenticated encryption at rest across every service — with envelope encryption and customer-managed keys when you need control.
- Category
- Identity & security
- Deployment
- Managed → air-gapped
- Governance
- IAM · encryption · audit
Three steps to running.
TLS in transit and authenticated encryption at rest, no config.
Envelope encryption with data keys wrapped by your KMS keys.
BYOK or hold-your-own for sovereign control; field-level where needed.
Encryption, in full.
In-transit and at-rest encryption with no extra configuration.
Data keys wrapped by KMS for scalable, auditable crypto.
Bring or hold your own keys for sovereign control.
Encrypt sensitive fields independently where required.
Provision it in a few lines.
Every service is reachable from the same SDK, CLI and infrastructure-as-code — one identity, one bill, one audit trail across the whole catalog.
# Provision encryption on Aether Cloud
aether identity-security create \
--service encryption \
--name app \
--region us-1 \
--deploy managed # or vpc | on-prem | air-gappedAt a glance.
- Transit
- TLS by default
- At rest
- Authenticated encryption
- Model
- Envelope encryption
- Keys
- BYOK / HYOK
- Granularity
- Field-level optional
Built for real work.
Data-at-rest protection
Regulated workloads
Sovereign key control
On one model, not stitched together.
The usual stack runs encryption in one product, the model in another and the data in a third — and the seams between them are the cost. Aether Cloud runs it on the same platform that serves the model, governs your identity and deploys into your boundary, with the rest of the catalog one hop away.
No stitching a vector DB to one place, a warehouse to another and a model to a third — encryption sits next to the rest of the catalog, one identity, one bill.
The provider that runs Aether runs your encryption — so the data and the model never leave the same governed boundary to talk to each other.
Need a capability that isn’t here yet? The model writes and deploys it into the same boundary — the catalog is a starting point, not a ceiling.
Good to know.
Yes — in transit and at rest across every service, with no extra configuration.
Yes — bring or hold your own keys for sovereign control.
Available where you need to protect specific sensitive fields independently.
Your boundary, your choice.
Pairs well with.
Fine-grained identity and access management with SSO, SCIM and short-lived credentials.
Centralized secrets with rotation, scoped access and full audit of every read.
Managed and customer-managed keys, HSM-backed, for encryption across every service.
Continuous posture management, findings and recommendations across your cloud footprint.
SOC 2 / ISO 27001 controls, evidence assembly and an immutable audit trail with provenance.
Policy-as-code guardrails and capability gating enforced across accounts and deployments.
Run Encryption on Aether Cloud.
Encryption in transit and at rest by default, with bring-your-own-key and envelope encryption. Deployable managed, in your VPC, on-prem or fully air-gapped — talk to us about the configuration your workloads and your boundary require.