Skip to main content

Security & Controls

Clear controls for sensitive payroll operations.

Aether combines organization-level data separation, role-based access, controlled approvals, protected sensitive information, authenticated access, and reviewable action records to help organizations manage payroll data with confidence.

Security that covers access, approvals, and operations

Security is not only about stopping outsiders. Aether's controls also help reduce excessive internal access, cross-organization access, accidental disclosure, improper approval or publishing, misuse of privileged accounts, untracked changes, and insecure release practices - within the client's approved operating model.

Core controls

  • Each organization's data stays protected

    Each organization's payroll data stays within its authorized workspace. Access is restricted to authorized users acting within that organization.

  • Role-based access

    Users see only the work their roles allow. Payroll preparation, review, approval, publication, administration, and employee access can be separated across roles.

  • Controlled approvals

    High-impact payroll actions can require review by a different authorized person before they take effect.

  • Protected sensitive data

    Sensitive payroll information is restricted to authorized workflows and masked in normal work areas where appropriate - including bank and statutory values.

  • Secure employee payslip access

    Employees see only their own published payslips when this feature is included.

  • A clear history of actions

    Important payroll and administrative actions produce reviewable records showing who acted, what changed, and when.

  • Authorized releases

    Engineering changes move through tested, scanned, and reviewed release paths before production deployment, with rollback procedures for controlled recovery.

  • Recovery and incident response

    Controlled rollback and recovery procedures help contain incidents and restore service safely. Aether maintains procedures to investigate, contain, recover from, and document suspected security incidents.

Controls that support serious operating volume

Scale testing also exercised access, isolation, and recovery behaviors. Here is what that means for buyers:

  • Authenticated access

    Access is limited to authenticated users and governed roles.

  • Tenant isolation

    Client operations remain separated.

  • Protected-run safety

    Protected Payroll results are not casually altered.

  • Durable recovery

    Controlled work can recover safely after interruption.

  • Stale-result detection

    Teams are warned when earlier results need recalculation.

  • Payroll-input lineage

    Inputs and consequences remain traceable to their source.

These describe tested operating controls—not SOC 2, ISO, WCAG, ADA, or other certification badges.

Access and identity

Access is tied to individual accounts and protected through authenticated sessions and role-appropriate permissions. Users operate only within their authorized organization context.

Payroll workflow controls

Payroll runs follow clear lifecycle steps rather than ad-hoc spreadsheet handoffs. Where configured, preparation and approval can be separated so high-impact actions require independent review.

Data protection

Organization-scoped records keep payroll data within each authorized organization context. Sensitive bank and statutory values are masked in normal display paths. Access to Aether services uses encrypted connections (HTTPS).

Secure employee payslip access

Employees can securely view their own published payslips when this feature is included. They see only their own authorized records.

Employee payslip access is configured within the client's approved operating model. This describes employee access to published payslips - not a full employee self-service suite as production GA.

  • Less manual payslip distribution
  • No shared employee file repository for published payslips
  • Clearer release history for authorized records
  • Direct employee access to authorized payslips
  • Controlled publication before employee visibility
  • Stronger privacy than unsecured attachments or paper-only distribution

Secure operations

Public assessment intake applies validation, rate limiting, and layered abuse controls. Operational access to marketing infrastructure is restricted to designated officers. Product and marketing changes are released through controlled, Git-backed deployment paths.

Incident and recovery readiness

Aether maintains procedures to investigate, contain, recover from, and document suspected security incidents affecting the marketing site and related intake systems. This describes operating practice - not continuous SOC staffing or a certification-badge claim.

How we describe controls

We describe controls in precise operating terms. This site does not publish SOC 2, ISO, or other security certification badges. Controls applied to each implementation depend on approved client scope, user roles, and operating requirements.

Discuss your security and payroll-control requirements

Tell us about your employee population, pay groups, schedules, Leave policies, integrations, and approval requirements.

Request an Assessment