Aerolith Studio

Security by boundary, not by appearance.

Aerolith separates public delivery, private application code, customer data, credentials, signing keys, and release artifacts. The foundation uses least privilege, signed entitlements, request throttling, accountable audit records, and customer-controlled deployment.

Private by default

Application configuration, signing material, logs, and data live outside the public web root.

Cryptographic trust

ES256 signatures let installations verify licenses and update manifests without receiving Aerolith’s private signing keys.

Durable operation

License validation confirms rights and update access without turning an Aerolith outage into a customer outage.

Accountable access

Human owner accounts and scoped service identities are separated and recorded.