AETERNUM // SECURITY & TRUST

Trust should beinspectable.

A direct record of what Aeternum software verifies, where authority remains, what can leave a device, and which claims we deliberately do not make.

01 // Operating principles

Security is a sequence, not a slogan.

These principles describe the controls implemented in Praesidium PC Defense 2.38.6. They are bounded claims—not a promise that software can eliminate every risk.

01

Evidence before action

Praesidium begins with measured system evidence and separates observation from any change.

02

Explicit authority

Protected work stays behind review and confirmation. A recommendation is not authorization.

03

Recovery

Consequential maintenance is paired with records, restore points, quarantine, or another stated recovery path where supported.

04

Least necessary access

Components request the access needed for the selected operation; the desktop does not receive payment secrets.

05

Explainable operations

Findings, confidence, limitations, and the intended effect of an action are presented in plain language.

06

Auditability

Praesidium records checked, approved, completed, and recoverable work in its local activity journal.

02 // Software integrity

A verifiable release path.

Praesidium is distributed as a Windows x64 installer through the official Aeternum download route and its public GitHub release record.

Release identity

Version 2.38.6 is the current stable public release, published September 1, 2026.

Code signing

The official installer is Authenticode-signed. Windows exposes the publisher signature before installation.

Binary digest

The release publishes SHA-256 394EC27C…2AAC8F9A. The complete value is recorded on the Release Record.

Update verification

The desktop verifies the signed update manifest and the downloaded package hash before launching an update.

Version record

Release dates, installer identity, integrity data, and verified changes are maintained on the public release page.

03 // Data & privacy

Local first. Remote only where the function requires it.

Routine diagnostics and maintenance evidence are processed on the Windows device. Online account services keep only the records needed for identity, licensing, billing references, downloads, and support.

LOCAL PROCESSING

System evidence stays local

Praesidium examines Windows system-state metadata, resource readings, event evidence, maintenance results, and selected file paths. It does not need private document contents to build its timeline.

ACCOUNT DATA

Scoped service records

Account identity, verification state, entitlements, license activations, registered devices, billing references, and support messages are handled by Aeternum’s account service.

WEBSITE ANALYTICS

Separate from desktop diagnostics

The public website uses Google Analytics 4 and Microsoft Clarity as described in the Privacy Policy. Authenticated account fields are masked. These tools are not the Praesidium diagnostic engine.

PAYMENTS

Stripe-hosted checkout

Checkout and refunds are executed server-side through Stripe. The desktop and browser interface never receive Aeternum’s Stripe secret key, and Aeternum does not store full card details.

LOCAL AI

Optional Ollama connection

When enabled and installed, advisory AI runs through the user’s local Ollama service. Praesidium’s deterministic tools remain usable without it.

DISABLED AI

No hidden substitute

Turning local AI off removes AI explanations; it does not transfer that work to a remote model or weaken action confirmations.

Full data terms

Read the current Privacy Policy for retention, service providers, account data, analytics, and user choices.

04 // Authority & AI

Advice cannot silently become action.

Praesidium’s local AI can explain evidence and suggest a next step. It cannot approve protected changes, bypass safeguards, or directly perform destructive maintenance.

OBSERVEANALYZEPRESENTREVIEWAUTHORIZEACTRECORD

The user authorizes. The same safety boundary applies in both Simple and Advanced views. See the complete AI Governance policy.

05 // Network activity

Online only for named operations.

Praesidium can work offline in Core, during the original trial, or from a previously verified cached paid state. Some selected features require a connection.

Account access

Sign-in, email verification, session renewal, and customer-portal requests communicate with the Aeternum account service.

Licensing

Activation, validation, and device deactivation exchange entitlement and device identifiers with the commerce gateway over HTTPS.

Updates

Update checks retrieve the signed manifest; approved downloads retrieve the official installer package.

User requests

Checkout, refund requests, downloads, and support conversations communicate only when the user initiates those workflows.

06 // Coordinated reporting

Report a vulnerability directly.

Send a concise description, affected version, reproduction steps, and the impact you observed. Do not include passwords, private keys, live payment data, or another person’s personal information.

Security contact

Email AeternumIT@proton.me with the subject “Security Report — Aeternum.” We will acknowledge the report and coordinate follow-up based on severity and reproducibility.