Security & Controls
Clear controls for sensitive payroll operations.
Security that covers access, approvals, and operations
Security is not only about stopping outsiders. Aether's controls also help reduce excessive internal access, cross-organization access, accidental disclosure, improper approval or publishing, misuse of privileged accounts, untracked changes, and insecure release practices - within the client's approved operating model.
Core controls
Each organization's data stays protected
Each organization's payroll data stays within its authorized workspace. Access is restricted to authorized users acting within that organization.
Role-based access
Users see only the work their roles allow. Payroll preparation, review, approval, publication, administration, and employee access can be separated across roles.
Controlled approvals
High-impact payroll actions can require review by a different authorized person before they take effect.
Protected sensitive data
Sensitive payroll information is restricted to authorized workflows and masked in normal work areas where appropriate - including bank and statutory values.
Secure employee payslip access
Employees see only their own published payslips when this feature is included.
A clear history of actions
Important payroll and administrative actions produce reviewable records showing who acted, what changed, and when.
Authorized releases
Engineering changes move through tested, scanned, and reviewed release paths before production deployment, with rollback procedures for controlled recovery.
Recovery and incident response
Controlled rollback and recovery procedures help contain incidents and restore service safely. Aether maintains procedures to investigate, contain, recover from, and document suspected security incidents.
Controls that support serious operating volume
Scale testing also exercised access, isolation, and recovery behaviors. Here is what that means for buyers:
Authenticated access
Access is limited to authenticated users and governed roles.
Tenant isolation
Client operations remain separated.
Protected-run safety
Protected Payroll results are not casually altered.
Durable recovery
Controlled work can recover safely after interruption.
Stale-result detection
Teams are warned when earlier results need recalculation.
Payroll-input lineage
Inputs and consequences remain traceable to their source.
These describe tested operating controls—not SOC 2, ISO, WCAG, ADA, or other certification badges.
Access and identity
Access is tied to individual accounts and protected through authenticated sessions and role-appropriate permissions. Users operate only within their authorized organization context.
Payroll workflow controls
Payroll runs follow clear lifecycle steps rather than ad-hoc spreadsheet handoffs. Where configured, preparation and approval can be separated so high-impact actions require independent review.
Data protection
Organization-scoped records keep payroll data within each authorized organization context. Sensitive bank and statutory values are masked in normal display paths. Access to Aether services uses encrypted connections (HTTPS).
Secure employee payslip access
Employees can securely view their own published payslips when this feature is included. They see only their own authorized records.
Employee payslip access is configured within the client's approved operating model. This describes employee access to published payslips - not a full employee self-service suite as production GA.
- Less manual payslip distribution
- No shared employee file repository for published payslips
- Clearer release history for authorized records
- Direct employee access to authorized payslips
- Controlled publication before employee visibility
- Stronger privacy than unsecured attachments or paper-only distribution
Secure operations
Public assessment intake applies validation, rate limiting, and layered abuse controls. Operational access to marketing infrastructure is restricted to designated officers. Product and marketing changes are released through controlled, Git-backed deployment paths.
Incident and recovery readiness
Aether maintains procedures to investigate, contain, recover from, and document suspected security incidents affecting the marketing site and related intake systems. This describes operating practice - not continuous SOC staffing or a certification-badge claim.
How we describe controls
We describe controls in precise operating terms. This site does not publish SOC 2, ISO, or other security certification badges. Controls applied to each implementation depend on approved client scope, user roles, and operating requirements.
Related capabilities
Discuss your security and payroll-control requirements
Tell us about your employee population, pay groups, schedules, Leave policies, integrations, and approval requirements.
Request an Assessment