Provider credential custody
Provider API keys are encrypted before database storage using AES-256-GCM. Raw provider credentials are not returned to the browser after storage. Applications call AetherGate with scoped gateway credentials instead of embedding every upstream provider key.
- AES-256-GCM encryption before provider credentials are persisted.
- Raw provider credentials are treated as write-only after storage.
- Customer applications use AetherGate gateway credentials rather than direct provider secrets.