Security
Security
Last updated: August 2026
How this website is protected
AERA is an early-access site, and we're direct about what protects it today. We don't claim certifications or audits we haven't completed — here is what is actually in place:
- All traffic to this website is encrypted over HTTPS.
- Every form submission is validated on the server, not just in your browser, before anything is stored.
- Administrative tools are access-controlled: each administrator has their own account and password, passwords are stored as salted, one-way hashes — never in plain text — and admin sessions use secure, HTTP-only cookies that aren't readable by browser scripts.
- Form submissions and login attempts are rate-limited to reduce automated abuse and spam.
- IP addresses used for spam and abuse prevention are stored as one-way hashes, not in raw form.
- Our database is only reachable from AERA's own server-side code, using credentials that are never exposed to the browser.
What we don't claim
We have not completed SOC 2, PCI DSS, or HIPAA certification, and we have not undergone a formal third-party security audit. We don't use the phrase “bank-grade security” because it isn't a defined standard. If any of this changes, we'll update this page.
Responsible disclosure
If you believe you've found a security issue with this website, please email jaiden@aerafinance.cloud with details. Please don't publicly disclose an issue before we've had a reasonable opportunity to address it.