Security and Data Protection
1. Security approach and scope
AeroDesk AI uses layered safeguards across accounts, business workspaces, public forms, customer communications, billing, connected services, and administrative operations.
Security controls are designed to reduce unauthorized access, accidental disclosure, fraud, abuse, repeated events, unsafe automation, and cross-business data exposure.
No internet service can promise perfect security. Controls are reviewed and improved as the product, providers, threats, and operating requirements change.
2. Authentication, sessions, and permissions
Private account and administrative pages require sign-in. You can access only the businesses and features allowed for your account.
PWA and home-screen app views use the same account and business access rules as the corresponding web experience; installing the PWA does not bypass sign-in or billing controls.
Important actions may require a fresh sign-in, business ownership, administrator access, active billing, confirmation, or support review.
If AeroDesk AI cannot confirm account access, it blocks the private page or action instead of showing protected information.
3. Business separation and data access
Customer chats, calls, recordings, transcripts, emails, leads, bookings, summaries, notes, settings, and follow-ups are associated with the correct business workspace.
Access rules are designed to prevent one business from seeing or changing another business’s private records.
Support access is limited to approved work. Your private business notes and billing history are not shown to your customers.
Public widgets and public forms receive only the configuration needed for the public experience and do not grant access to the private dashboard.
4. Data protection and retention
Encrypted network connections and provider security controls help protect information while it is transmitted and stored through the services that operate AeroDesk AI.
Retention is based on the type of record, your settings, active service needs, security, billing, dispute handling, consent, opt-out suppression, and legal requirements.
Call recordings and transcripts can use the expiration settings you choose. Expired call data is removed when the connected service supports deletion.
Deletion and account-closure requests are reviewed so active subscriptions, phone services, billing history, integrations, customer records, legal holds, and security evidence are handled safely.
5. Public forms, communications, and abuse protection
Public chat, callback demos, lead forms, and payment pages check submitted information and use limits and bot protection to reduce abuse.
AeroDesk AI checks incoming service updates before changing an account. Duplicate protection helps prevent the same payment, message, notification, or task from running twice.
Consent, STOP and START handling, do-not-contact records, sending windows, and workflow limits help reduce unwanted or repeated communication.
AeroDesk AI may block, delay, limit, or suspend traffic and features that create spam, fraud, security, provider, or customer-safety risk.
6. Billing and payment security
Card entry and payment confirmation use Stripe-hosted payment services. AeroDesk AI does not store raw card numbers or card security codes.
Prices, discounts, setup fees, subscriptions, and paid access are confirmed by protected payment systems rather than values entered by the browser alone.
Payment checks, duplicate protection, fraud screening, bank verification when required, and account records help protect billing.
References to a payment or infrastructure provider’s certification apply to that provider. They do not mean AeroDesk AI has received the same independent certification unless AeroDesk AI states that explicitly.
7. Connected services and administrative operations
Email, phone, voice, AI, calendar, automation, analytics, and other connected services receive only the information needed for the enabled workflow.
Private service credentials and administrative settings are not shown on public or customer-facing pages.
Updates from connected services are checked where supported, and duplicate protection is used before changing customer, communication, billing, or account information.
You should connect only services you are authorized to use and remove old integrations, forwarding rules, users, devices, and permissions when they are no longer needed.
8. Monitoring, incidents, and service recovery
Service records and security events may be reviewed to investigate failures, abuse, unauthorized actions, and service health.
When a material risk is detected, AeroDesk AI may restrict traffic, pause a workflow, preserve relevant evidence, require verification, notify you if your account is affected, or coordinate with a service provider.
Backups, recovery tools, and tested releases support service recovery, but AeroDesk AI cannot promise uninterrupted availability.
Security incidents are assessed based on the information involved, affected systems, impact on your business, legal duties, provider responsibilities, and the steps needed to contain and correct the issue.
9. What you should do
Use a strong unique password, protect email access, enable available account protections, and never share authentication codes or private sign-in links.
Invite only people who need access, assign the minimum appropriate role, and remove staff, contractors, devices, forwarding rules, and integrations when access is no longer required.
Keep business information, customer-facing notices, owner contact details, booking and review links, phone routing, retention choices, and emergency or human-handoff settings accurate.
Review connected tools and AI workflows before enabling them with customer information. Do not place full payment information, passwords, or unrelated sensitive data into calls, chats, prompts, notes, or support attachments.
Notify AeroDesk AI promptly if you suspect account compromise, incorrect access, exposed customer information, unauthorized provider changes, or abusive use.
10. Responsible disclosure and security claims
If you believe you found a security issue, email support@aerodeskai.com with a clear description and safe reproduction details. Do not access, copy, change, delete, retain, or share data that is not yours.
Do not use testing to disrupt service, contact customers, trigger live calls or messages, create charges, access another account, or weaken a protection without written authorization.
We review good-faith reports and may request additional information, restrict affected traffic, or coordinate remediation with relevant providers.
This page describes current security practices in plain language. It is not a warranty that the service cannot be breached and does not claim AeroDesk AI holds a certification unless that certification is explicitly identified as belonging to AeroDesk AI.