TRUST
Aether subprocessors
Every third party that processes data on Aether's behalf, what reaches it, where it is, how long it is kept, and the terms it is held to.
Updated 19 August 2026
Aether Forge operates the Aether platform. This page lists every third party that processes data on Aether’s behalf, what data reaches it, the region it is processed in, how long the provider says it keeps that data, and where its terms can be read.
It is the list the contract pack’s Data Processing Schedule points at. It is
maintained in the Aether repository (docs/security/subprocessors.md) and
published from that one file, so the version a firm reads and the version Aether
holds are the same text.
Last reviewed: 19 August 2026. A material new subprocessor is notified to firms under contract before it starts processing, per the Master Terms.
The list
| Provider | Purpose | Data that reaches it | Region | Retention | Terms |
|---|---|---|---|---|---|
| Anthropic PBC (United States) | Claude API — the model behind Vesper, meeting analysis, document and portfolio extraction, document narrative, and migration mapping suggestions | Only what the used feature sends: household and member names, summary figures, published advice text, meeting transcripts, statement page text, uploaded portfolio files. See AI data handling for the per-feature breakdown | United States. Aether does not pin a region for these calls | Anthropic states it deletes API inputs and outputs within 30 days of receipt or generation, except where content is flagged by its trust and safety systems (up to 2 years) or the law requires longer | Commercial Terms · Retention policy · Training policy · API retention docs |
| DigitalOcean, LLC (United States company, Sydney region) | The application server (droplet), the managed PostgreSQL 18 database, and object storage for client documents | All application data — every client record, document, and audit row Aether holds | Sydney (syd1) for droplet, database and Spaces | For the life of the service; database backups follow the managed backup policy. Deletion at contract exit follows Aether’s own retention procedure | DPA · Privacy policy |
| GitHub, Inc. (United States) | Source repository, CI, and the container image registry | Source code, built container images, release evidence. No client data | GitHub-hosted | For the life of the repository | Data Protection Agreement |
| Cloudflare, Inc. (United States) | Authoritative DNS for aetherforge.au and its subdomains | DNS records only. Cloudflare is not in the request path: it resolves names, it does not proxy traffic. TLS terminates on Aether’s own server with its own certificate, so Cloudflare never sees a request, a session or any client data. It does see the DNS queries resolvers make for Aether’s hostnames | Anycast, global | DNS query logs per Cloudflare’s policy | Customer DPA · Privacy policy |
| Hostinger International (Lithuania/EU) | Mailboxes for Aether’s own @aetherforge.au addresses — the contact and support address a firm writes to | Whatever a sender puts in an email to Aether. That can include client names or details when a firm writes to support about a specific case, so it is listed rather than treated as ordinary business correspondence. Aether’s outbound product email does not go through Hostinger — that is Resend, below | Provider-hosted (EU) | Per Hostinger’s policy; a mailbox retains what is not deleted | DPA · Privacy policy |
| Resend, Inc. (United States) | Transactional email | Recipient address, subject, HTML body; client-portal invitation and reset links; advice documents a firm chooses to email, as PDF attachments | Provider-hosted | Per Resend’s policy; Aether keeps no copy beyond its own outbox rows | DPA · Privacy policy |
| Microsoft Corporation (Teams incoming webhooks) | Notification cards delivered to a channel in the firm’s own Microsoft tenant, when the firm configures one | Household names, file names and types, task text, deadlines, billing notices | The firm’s own Microsoft tenant | Governed by the firm’s own Microsoft retention settings | Products and Services DPA |
| Stripe, Inc. (United States; Stripe Payments Australia Pty Ltd for Australian merchants) | Subscription billing | Firm billing contact, seat counts, payment-method tokens. Card and bank details are entered into Stripe-hosted fields and never held by Aether | Provider-hosted | Per Stripe’s policy and Australian record-keeping obligations | DPA · Privacy policy |
| Basiq Pty Ltd (Australia) — not live in production | Open banking / bank feeds. An Accredited Data Recipient under the Consumer Data Right | Account and transaction data for consenting clients | Australia | Under the CDR rules: deleted or de-identified when consent expires or is withdrawn, except where Australian law requires retention | CDR policy · CDR compliance |
| Functional Software, Inc. (Sentry) (United States) — only when a DSN is configured | Error monitoring | Exception reports with personal information disabled and local variables suppressed, passed through Aether’s own scrubber. Disabled entirely when no DSN is set | Provider-hosted | Per Sentry’s policy | DPA |
| Internet Security Research Group (Let’s Encrypt) | TLS certificates for Aether’s domains | Domain names only. No client data | — | Per ISRG’s policy | Privacy policy |
Where the site and the app actually run
DNS is Cloudflare’s; everything the DNS points at is Aether’s own server at DigitalOcean. The marketing site, the adviser application and the client portal are all served from that one droplet behind Caddy, with certificates from Let’s Encrypt. If Cloudflare’s proxy were ever switched on for these hostnames, Cloudflare would terminate TLS and become a processor of everything a browser sends — a different entry from the one above. It is off as at 18 August 2026, verified from the live DNS records and the response headers.
Loaded by the browser, not by Aether
The adviser application and client portal currently load a charting library, a font and an icon set from third-party content-delivery networks (jsDelivr, Google Fonts, cdnjs), and the billing page loads Stripe.js. Those hosts receive the browser’s IP address and request headers when a page loads. They receive no client data and they are not subprocessors of Aether — but they are a disclosure a reviewer should have. Aether is self-hosting these assets under hardening item SEC-3, after which this paragraph is removed.
Not subprocessors
Two things that look like subprocessors and are not:
- A firm’s own Microsoft Teams channel. When a firm configures its own incoming webhook, Aether sends notification cards to that firm’s Microsoft tenant at the firm’s direction. That is the firm’s own disclosure, made under the firm’s own Microsoft agreement.
- A firm’s own email recipients. Advice documents a firm chooses to email from Aether travel through Resend (listed above) to addresses the firm chooses.
Overseas disclosure
The AI model provider, the transactional email provider, the payment processor and the source-control provider process data outside Australia. Hosting, database and document storage remain in the Sydney region. Where Aether discloses personal information overseas it takes the steps required by the Australian Privacy Principles, and a firm remains responsible for its own clients’ privacy notices and consents.
Questions
Email reid@aetherforge.au. A firm under contract can ask for the current list at any time and is notified before a material new subprocessor starts processing.