Skip to content
Apex
Aether Cloud · Identity & security

Encryption.

Encryption in transit and at rest by default, with bring-your-own-key and envelope encryption.

⊞ Identity & security
Overview

Encryption everywhere by default — TLS in transit and authenticated encryption at rest across every service — with envelope encryption and customer-managed keys when you need control.

Where it sits
Deployment
Managed → air-gapped
Governance
IAM · encryption · audit
How it works

Three steps to running.

01
On by default

TLS in transit and authenticated encryption at rest, no config.

02
Wrap with KMS

Envelope encryption with data keys wrapped by your KMS keys.

03
Control keys

BYOK or hold-your-own for sovereign control; field-level where needed.

What you get

Encryption, in full.

On by default

In-transit and at-rest encryption with no extra configuration.

Envelope encryption

Data keys wrapped by KMS for scalable, auditable crypto.

BYOK / HYOK

Bring or hold your own keys for sovereign control.

Field-level

Encrypt sensitive fields independently where required.

API-first

Provision it in a few lines.

Every service is reachable from the same SDK, CLI and infrastructure-as-code — one identity, one bill, one audit trail across the whole catalog.

# Provision encryption on Aether Cloud
aether identity-security create \
  --service encryption \
  --name app \
  --region us-1 \
  --deploy managed   # or vpc | on-prem | air-gapped
Specs

At a glance.

Transit
TLS by default
At rest
Authenticated encryption
Model
Envelope encryption
Keys
BYOK / HYOK
Granularity
Field-level optional
Use cases

Built for real work.

01

Data-at-rest protection

02

Regulated workloads

03

Sovereign key control

Why one platform

On one model, not stitched together.

The usual stack runs encryption in one product, the model in another and the data in a third — and the seams between them are the cost. Aether Cloud runs it on the same platform that serves the model, governs your identity and deploys into your boundary, with the rest of the catalog one hop away.

One platform

No stitching a vector DB to one place, a warehouse to another and a model to a third — encryption sits next to the rest of the catalog, one identity, one bill.

The model is here

The provider that runs Aether runs your encryption — so the data and the model never leave the same governed boundary to talk to each other.

Built on demand

Need a capability that isn’t here yet? The model writes and deploys it into the same boundary — the catalog is a starting point, not a ceiling.

FAQ

Good to know.

Is encryption on by default?

Yes — in transit and at rest across every service, with no extra configuration.

Can I control the keys?

Yes — bring or hold your own keys for sovereign control.

Field-level encryption?

Available where you need to protect specific sensitive fields independently.

Deploy anywhere

Your boundary, your choice.

Managed
Your VPC
On-prem
Air-gapped / sovereign

Run Encryption on Aether Cloud.

Encryption in transit and at rest by default, with bring-your-own-key and envelope encryption. Deployable managed, in your VPC, on-prem or fully air-gapped — talk to us about the configuration your workloads and your boundary require.