Private by default
Application configuration, signing material, logs, and data live outside the public web root.
Aerolith Studio
Aerolith separates public delivery, private application code, customer data, credentials, signing keys, and release artifacts. The foundation uses least privilege, signed entitlements, request throttling, accountable audit records, and customer-controlled deployment.
Application configuration, signing material, logs, and data live outside the public web root.
ES256 signatures let installations verify licenses and update manifests without receiving Aerolith’s private signing keys.
License validation confirms rights and update access without turning an Aerolith outage into a customer outage.
Human owner accounts and scoped service identities are separated and recorded.