Security architecture

Raw customer data never lives in Aeris.

Your warehouse stays the source of truth. Aeris activates anonymized tokens, cohorts, and outcomes into the tools you approve - then lets AI analyze, optimize, and execute inside your guardrails.

No raw PII stored
Only changed rows sync
Read-only until approved
Every action audited

Source of truth

Warehouse / CDP

Stays your source of truth

Commerce systems

Catalog, orders, outcomes

Ad accounts

Read-only by default

Aeris boundary

No raw PII database

Hash / tokenize
Cohorts
Outcomes
Guardrails

Activated destinations

Google AdsGoogle Ads
MetaMeta
TikTokTikTok
Amazon AdsAmazon
KlaviyoKlaviyo
ShopifyShopify

In one line

We never hold your raw PII.

We hold anonymized tokens, cohorts, campaign configuration, audit trails, and purchase outcomes from our network - so AI can act without turning Aeris into a second customer database.

Two simple paths

Raw PII stays where it belongs.

One path activates approved audiences. The other supports commerce media and RTB. Both start with hashing and expose only tokens or cohorts.

How data moves

Activation path

For CRM and ad audiences, PII is hashed before Aeris receives it.

raw

Source

raw data stays here

sha256

Before leaving

PII -> token

Aerisscore

Operate

cohorts + outcomes

approved

Sync

Ads / CRM

Aeris works with tokens and cohorts, not raw customer records.

Commerce media & RTB

Clean-room path

For media buying, matching happens on tokens and bidders see cohort signals only.

private

Hash

hashed on your side

Clean roomno raw

Join

match on tokens

TOKENcohort

Bid request

cohort_42 only

no PII

RTB

DSP / SSP

Bidders receive a cohort label, never a customer identity.

Aeris Vault

Security one-pager
The Real Group

Partner trust brief

Your commerce data, on your terms.

You control access, approval, revocation, and deletion. Aeris keeps raw customer records out of its database.

Read-only by defaultAES-256 encryptedDelete anytime
No raw PII stored
Read-only by default
Approve and audit
Revoke or delete

What crosses the boundary

Not stored does not mean never touched. Raw identifiers can be processed transiently for hashing or approved sync, but are not persisted as raw customer records.

Does not store

Raw emails or phone numbersFull customer profilesUnhashed identity graphs

May hold

Hashed tokensCohorts and scoresPurchase outcomesSettings and audit logs
Example: email@example.com -> token_a8f3k9 -> cohort_42

Compliance & access

SOC 2 Type II infraISO 27001 infraAES-256 at restTLS 1.2+ in transitGDPRCCPA

Built on provider-certified infrastructure and connected through official partner programs - never scraped access.

4,000+ retailers and brands in the Realry network

Your data stays yours - isolated, encrypted, read only, and deletable anytime.

Review security with us

๊ธฐ๋ณธ์œผ๋กœ ์ถฉ์กฑํ•˜๋Š” ๋ณด์•ˆ ํ‘œ์ค€

SOC 2 Type II ยท ISO 27001 ์ธ์ฆ ์ธํ”„๋ผ ์œ„์— ๊ตฌ์ถ•.

SOCTYPE IIINFRA
GDPR
AES-256AT REST
CCPA
ISO 27001INFRAINFRASTRUCTURE

SOC 2 Type II ยท ISO 27001 ์ธ์ฆ ์ธํ”„๋ผ ์œ„์— ๊ตฌ์ถ•.

Amazon Web ServicesAWS
MongoDB AtlasMongoDB Atlas
CloudflareCloudflare
StripeStripe

๊ฒ€์ฆ๋œ ์ปค๋จธ์Šค ๋ฏธ๋””์–ด ์•ก์„ธ์Šค

Aeris๋Š” ๊ณต์‹ ์ธ์ฆ ํŒŒํŠธ๋„ˆ ํ”„๋กœ๊ทธ๋žจ์„ ํ†ตํ•ด ์—ฐ๊ฒฐ๋ฉ๋‹ˆ๋‹ค โ€” ์Šคํฌ๋ž˜ํ•‘์ด๋‚˜ ์šฐํšŒ ์ ‘๊ทผ์ด ์•„๋‹™๋‹ˆ๋‹ค.

Amazon Ads Verified PartnerGoogle CSS Comparison Shopping Service

Connect with confidence, backed by clear controls.

Aeris keeps raw PII out of its database, keeps your source systems authoritative, and gives partners controls they can review: approval, audit, revocation, and deletion.