Trust
Trust & security.
How we protect identity data, how the platform is designed for safety by default, and how to report a vulnerability to us.
The defaults
Nothing you have to remember to turn on
See the product-level security page for the full technical defaults — encryption at rest, mandatory PKCE, anti-CSRF state + ID-token nonce, RS256-signed JWTs with JWKS rotation, single-use refresh tokens, rate-limited auth endpoints, HMAC-signed webhooks, immutable audit log.
Responsible disclosure
Found a vulnerability?
Email security@aerosol.so with a description of the issue, repro steps, and the impact you believe it has. We acknowledge every report within one business day, will keep you updated as the fix lands, and credit you in the release notes if you want public attribution.
What we ask
- · Do not exfiltrate user data, run mass scans, or impact other users while testing.
- · Give us a reasonable window to fix before public disclosure. We aim to fix critical issues within 14 days.
- · Report to security@aerosol.so rather than to public channels first.
Common questions
security@aerosol.so.
Email is the fastest path. PGP key available on request.
