Security & Trust

Boring security. On purpose.

We're a small company asking brands to trust us with their market position. Here is exactly how we handle data, what we never touch, and where the limits of our methods are.

The most important fact on this page

We never see private AI conversations.

Every conversation in Aethon's dataset is one we ran ourselves: simulated moment prompts against ChatGPT, Gemini, Claude, and Perplexity through their public interfaces and APIs. We have no access to any real user's chats, on any platform, and we would not want it. The product works on how models answer, not on who asked.

Controls

How your data is handled.

Encryption everywhere
TLS 1.2+ in transit, AES-256 at rest, for every workspace on every plan. No exceptions, no legacy paths.
Minimum data by design
Visibility tracking needs only your brand and product facts. Attribution adds a lightweight pixel. We never require customer PII, and we ask you not to send it.
Least-privilege access
Production access is role-scoped, logged, and reviewed. We can tell you exactly who can touch your workspace, because the list is short.
Your data leaves with you
Baselines, briefs, dashboards, and history are exportable at any time, including after cancellation. Deletion on request, confirmed in writing.
Enterprise controls
SSO and SAML available, SCIM and audit logs on Enterprise, custom DPA on request. If your security team has a questionnaire, we answer it ourselves.
Honest about maturity
We're early. Formal certifications like SOC 2 are on the roadmap, not on the wall yet. Until then we'll show you the actual controls instead of a badge.
Method ethics

What we will never do to win a recommendation.

Trust is the asset AI recommendations run on. Techniques that trick models burn it for everyone, and they stop working at the next release anyway.

No prompt injection. No hidden text, no adversarial instructions embedded in pages.
No paid placement schemes. There is no auction inside AI assistants, and anyone selling one is selling something else.
No fabricated claims or fake reviews. Every claim we ship for you is one you approved and can source.
No platform terms violations. Simulation runs within each platform's usage policies.

Found a vulnerability?

Tell us directly and we'll respond within one business day: daniel.arons@aiaethon.com. Good-faith research is welcome; we don't pursue researchers who report responsibly.

Security questionnaire? Send it.

We answer it personally, usually within two business days.