A public deploy on a free tier.
The fastest path to "it's live" is a public URL — org-blind and data-blind. It's where agent output leaks, not where a company's operating picture should live.
Your engineers are already shipping AI-built internal tools — you just can't see them yet. Aptarium isn't a tool you buy to block them; it's the legible place you send them, so every readout lands somewhere with a named owner: every edition carries a byline (a stable, dated copy the whole team opens, naming whose access it went out on, and as of when), live reads carry the viewer's own access, there is no standing shared credential anywhere, and nothing is public by default.
None of these are hypothetical. They're the default homes an agent-built readout lands in when there's no sanctioned one. And most leaders can't see them: in Retool's survey, only 5% of leaders were very confident they can see every internal tool running in production.2
The fastest path to "it's live" is a public URL — org-blind and data-blind. It's where agent output leaks, not where a company's operating picture should live.
Alive only while a laptop is open; shared by screen-share; gone when the maker is on leave.
It reads your data as its maker's login — a standing shared credential that never expires and follows the maker even after they change teams or leave.
Industry research is blunt about the base rate: Veracode found 45% of AI-generated code introduces an OWASP Top-10 vulnerability,1 and independent scans of vibe-coded apps keep surfacing exposed secrets and PII. Every one of those apps deployed somewhere.
The through-line: each of these leaves a standing shared credential — a single credential, readable by whoever opens the page, that outlives the person who made it. Aptarium holds none: live reads carry each viewer's own access, every shared view is an edition with a byline, and there is no standing shared credential anywhere.
Live connector reads run against the viewer's own connected account, through a sequence of proxy access checks (Jira shown as the worked example; each connector has its own read allowlist). There is no code path that reads as one shared login — so a shared URL can never over-expose.
Pairing the agent mints a 90-day token scoped to read data, read apps, and deploy apps; share management is an explicit opt-in. It rotates on rerun and is revoked on any failed configuration.
Named teammates, spaces, whole-org, or expiring guests scoped to a single readout. Nothing is public by default; no anonymous links exist.
A published edition names the person whose access it went out on and the moment it went out; a scheduled publish re-runs as its last human byline. No shared view is ever anonymous.
Content-addressed deploys mean rollback is a single command, and the version history is a tamper-evident record.
Deploy, share, connect, token, edition, billing, and admin actions land in a unified audit and proxy audit you can query.
These aren't gaps we'll close later. They're the boundary of the product, on purpose.
Every connector's access is read-only and allowlisted (Jira shown as the worked example). There is no code path that writes to a source system.
Every readout requires sign-in. There is no public gallery, no discovery, no watermark-and-share.
Aptarium is not a builder. Your code and your data never enter a model Aptarium runs — there is nothing to prompt-inject and no model context to leak into.
Live reads use each viewer's own access; the only shared form is an edition — a stable, dated copy carrying a byline: the person whose access it went out on, as of when — that a named person deliberately published.
Row-level security is forced on tenant tables; a query can only ever see its own workspace.
The proxy boundary, the access-check sequence, and where each viewer's identity is applied — walked through on the product page.
Hosting (Railway), Postgres, object storage (S3 / Tigris), transactional email (Resend), billing (Stripe), and Google OAuth (sign-in). Production identity is Google sign-in only; we notify you before adding any subprocessor to the data path.
Proxy cache and snapshot artifacts are data-at-rest with documented retention; account deletion has a seven-day cancellation window and pseudonymizes profile fields. See retention.
A Data Processing Agreement template is available on request.
A Consensus Assessments Initiative Questionnaire, filled to current state, available under NDA.
Live service health at status.
We are not yet SOC 2 certified, and we will not claim a completed report we don't have. We'll be straight with you about our current security posture and timeline during your review.
This page is built to be forwarded. Send it to whoever owns your security review — the architecture, the boundary, and the trust artifacts are all here, sales-free. When you're ready, join the waitlist and we'll loop your security team in during onboarding.
Cohorts invited weekly.
https://staging.patchbraid.info/security/teams