Security and data handling
A certificate platform is only as trustworthy as its boundaries. aethercert is built so that the control plane never holds a private key, nothing connects into your network, and every piece of code that runs on your hosts is signed.
Agent host
generated here · used here
Appliance
sent by the agent over your network
Certificate connector
encrypted local store
aethercert control plane
metadata only: serial, fingerprint, validity
Keys are generated where they are used
Generated on the host
The agent generates the key pair and CSR locally for every issuance and renewal. The control plane only receives metadata: serial, fingerprint, names and validity.
Delivered inside your network
For an appliance target, the agent sends the key straight to the appliance over its management API on your network.
Commercial certificates
The certificate connector keeps PSW Group keys in an encrypted local store and releases them only to agents holding a single-use, job-bound token - optionally only to agents approved on that host.
Outbound-only components
No inbound access
Agents and connectors poll the control plane over HTTPS. Nothing in the cloud opens a connection into your network.
Single-use signing tokens
The AD CS connector accepts a request only with a short-lived token minted for that job, checks the requested names against it and confirms it with the control plane before submitting.
Declared permissions
Registry packages declare the hosts, secrets and key material they use; the agent enforces the declaration.
Signed releases and signed packages
Verified updates
The Update Service checks every new build's SHA-256, size and Ed25519 signature before installing it. Windows binaries are Authenticode-signed.
Controlled rollout
Release channels, staged rollout, version pinning and rollback decide when a host gets a new build.
Signed deployment packages
Target Registry packages are signed and pinned per installation. Community packages are off until an admin enables them.
Script gate
Custom scripts only run from a root- or administrator-owned directory that nobody else can write to.
Who can do what
Mandatory MFA
Every member uses a second factor; passkeys are supported. Sign-in attempts are rate-limited with escalating lockout.
Single sign-on
Connect your own Microsoft Entra ID app registration so your Conditional Access applies.
Roles
Viewer, member, admin and owner. Deploy targets, which run code on hosts, can only be configured by admins.
Tenant isolation
Organizations are isolated with database row-level security, not only in application code. MSP staff can be scoped to individual customers.
Secrets, audit and residency
Encrypted credentials
DNS tokens, appliance passwords and CA credentials are encrypted by the application with AES-256-GCM and never returned to the browser.
Audit trail
The event log records every change with its actor, for 7, 30 or 90 days depending on plan.
Hosted in Germany
The application runs at Hetzner in Nuremberg; the database is in Frankfurt.
Your data
Members can export their data and delete their account from the dashboard.
Related features
Documentation
Frequently asked questions
Security
Can aethercert staff read my private keys?
No. Private keys are never sent to the control plane, so there is nothing there to read.
Does aethercert hold security certifications?
aethercert does not currently advertise any certification. The documentation describes the controls in detail so you can assess them yourself.
How do I report a vulnerability?
Email [email protected] or use private vulnerability reporting on GitHub. Please do not open a public issue.
Review it in detail
The security documentation covers key handling, encryption, hosting and reporting.
Community plan, no card required. Open registration - your account is ready in a few minutes.