Security & trust
How Aided7 handles your account, code, and data.
Authentication
Email/password plus Google and GitHub sign-in (Supabase Auth). Passwords are never stored in plain text.
Data in transit & at rest
All traffic is encrypted over HTTPS. Projects, generated code, and artifacts are stored with access scoped to you only.
Code ownership
Rights to the code and artifacts you generate belong to you. We don't use them beyond operating and improving the service.
Add-in licensing
Distributed add-ins run only for the signed-in account, protected by signed tokens, response signing, and seat limits (with an offline grace period).
What we commit to
- Least privilege — data is accessible only to your account.
- Runtime exceptions (5xx) are monitored for fast response.
- Admin access is split into Master / Operator roles.
In progress / planned
- Secure subscription/payment integration
- Data Processing Agreement (DPA) and a detailed security overview
- Reviewing external audits and certifications (SOC 2 / ISMS)
Please report security vulnerabilities privately by email instead of the public board: