aethercert
Security

Security and data handling

A certificate platform is only as trustworthy as its boundaries. aethercert is built so that the control plane never holds a private key, nothing connects into your network, and every piece of code that runs on your hosts is signed.

Where private keys are created, stored and used.
01Private keys

Keys are generated where they are used

Generated on the host

The agent generates the key pair and CSR locally for every issuance and renewal. The control plane only receives metadata: serial, fingerprint, names and validity.

Delivered inside your network

For an appliance target, the agent sends the key straight to the appliance over its management API on your network.

Commercial certificates

The certificate connector keeps PSW Group keys in an encrypted local store and releases them only to agents holding a single-use, job-bound token - optionally only to agents approved on that host.

02Architecture

Outbound-only components

No inbound access

Agents and connectors poll the control plane over HTTPS. Nothing in the cloud opens a connection into your network.

Single-use signing tokens

The AD CS connector accepts a request only with a short-lived token minted for that job, checks the requested names against it and confirms it with the control plane before submitting.

Declared permissions

Registry packages declare the hosts, secrets and key material they use; the agent enforces the declaration.

03Software supply

Signed releases and signed packages

Verified updates

The Update Service checks every new build's SHA-256, size and Ed25519 signature before installing it. Windows binaries are Authenticode-signed.

Controlled rollout

Release channels, staged rollout, version pinning and rollback decide when a host gets a new build.

Signed deployment packages

Target Registry packages are signed and pinned per installation. Community packages are off until an admin enables them.

Script gate

Custom scripts only run from a root- or administrator-owned directory that nobody else can write to.

04Access

Who can do what

Mandatory MFA

Every member uses a second factor; passkeys are supported. Sign-in attempts are rate-limited with escalating lockout.

Single sign-on

Connect your own Microsoft Entra ID app registration so your Conditional Access applies.

Roles

Viewer, member, admin and owner. Deploy targets, which run code on hosts, can only be configured by admins.

Tenant isolation

Organizations are isolated with database row-level security, not only in application code. MSP staff can be scoped to individual customers.

05Data

Secrets, audit and residency

Encrypted credentials

DNS tokens, appliance passwords and CA credentials are encrypted by the application with AES-256-GCM and never returned to the browser.

Audit trail

The event log records every change with its actor, for 7, 30 or 90 days depending on plan.

Hosted in Germany

The application runs at Hetzner in Nuremberg; the database is in Frankfurt.

Your data

Members can export their data and delete their account from the dashboard.

Frequently asked questions

Security

Can aethercert staff read my private keys?

No. Private keys are never sent to the control plane, so there is nothing there to read.

Does aethercert hold security certifications?

aethercert does not currently advertise any certification. The documentation describes the controls in detail so you can assess them yourself.

How do I report a vulnerability?

Email [email protected] or use private vulnerability reporting on GitHub. Please do not open a public issue.

Review it in detail

The security documentation covers key handling, encryption, hosting and reporting.

Community plan, no card required. Open registration - your account is ready in a few minutes.