Data Security and Encryption
Aerca is an early-stage finance-operations product. This page distinguishes safeguards used in the current desktop prototype from controls planned for future hosted integrations and production pilots. We will update these disclosures as the architecture and independent assurance mature.
1. Current Prototype Safeguards
The current Windows desktop prototype is designed around local processing and user-controlled access:
- Encrypted Local Ledger: supported local records are stored in SQLite through SQLCipher rather than an unencrypted local database.
- Credential Storage: supported API keys and secrets are stored through Windows Credential Manager rather than embedded in ordinary project files.
- Customer-Controlled Models: the prototype can support bring-your-own-key access to selected model providers or local models, allowing the user to control which provider receives a request.
- Human Approval: client-facing and money-related actions are intended to remain reviewable and user-approved.
2. Imported Files and Planned Hosted Storage
The current prototype can import user-selected CSV and Excel files for local analysis. Users should provide only the information needed for the test workflow and should avoid unnecessary regulated or highly sensitive data. If Aerca later introduces hosted file storage, the production design is expected to include:
- private, access-controlled storage;
- encryption in transit and at rest using the selected infrastructure provider's supported controls;
- time-limited access mechanisms and least-privilege permissions where appropriate; and
- file validation, logging, retention controls, and security testing before broader production use.
3. Artificial Intelligence Privacy and Data Siloing
Aerca may use AI models to analyze imported operational and financial data, explain risks, and prepare drafts. The selected provider, deployment mode, and account settings determine how a model request is processed.
- No Aerca Model Training: Aerca does not use customer financial data to train a public or shared Aerca model unless a customer separately and explicitly agrees to a defined use.
- Provider Terms: third-party AI providers may apply their own retention, security, and model-training terms. Those terms should be reviewed before a provider is selected or connected.
- Data Minimization: product workflows should send only the information reasonably required for the requested analysis.
- Future Isolation: hosted production pilots are planned to use account-level access controls and logical data separation appropriate to the architecture in use.
4. Planned Third-Party Integrations
Aerca plans to connect to accounting, project-management, time-tracking, invoicing, email, payment, and model providers. Before a production integration is enabled, Aerca intends to:
- use official provider APIs and authorization methods where available;
- request the minimum permissions reasonably needed for the selected workflow;
- prefer read-only access when write access is not required;
- document what data is accessed and how access can be revoked; and
- avoid asking users to share third-party passwords directly with Aerca.
5. Transparency, Accountability, and Incident Response
Aerca is developing security-review and incident-response procedures appropriate to the sensitivity of financial and operational data:
- Testing: security testing and review will expand before wider production access. We do not currently claim completed independent penetration testing or certification.
- Response: suspected incidents will be investigated, contained, documented, and communicated to affected users when required by applicable law and the circumstances.
- Improvement: verified incidents will inform remediation and future product safeguards.
6. Data Ownership, Portability, and Right to Erasure
You retain ownership of the business data you provide. Aerca does not sell that data to data brokers or advertisers. Export and deletion capabilities will depend on the product workflow and architecture in use; verified requests will be handled subject to applicable law, legitimate retention needs, and reasonable backup-retention periods.
7. Responsible Disclosure
We welcome collaboration with the global cybersecurity community. If you discover a vulnerability in our systems, we ask that you report it to us responsibly via the contact form on our homepage. We evaluate all reports with the highest priority and will work swiftly to resolve verified issues.