Security
Last updated October 6, 2026
Your unreleased episodes and your podcast host credentials deserve care. Here's how Afterair handles them.
Your audio
- Uploaded audio goes to a private storage bucket. Each workspace can only read and write its own folder.
- Audio is deleted at most 30 days after processing by default, and you can change that in settings.
- Uploads are resumable, so a dropped connection doesn't mean starting over.
Your account data
- All traffic is encrypted with TLS, and HTTPS is enforced with HSTS.
- Every table is protected by row-level security, so a signed-in user can only reach their own workspace's rows.
- Privileged operations (charging and refunding credits, publishing) run only on our servers after an ownership check.
- Passwords are handled by our authentication provider and stored only as salted hashes.
Integration tokens
- Podcast host tokens, such as your Buzzsprout or Transistor API key, are encrypted at rest with AES-256-GCM.
- They are decrypted only on the server at the moment we publish, and are never sent back to your browser.
- Disconnecting an integration deletes the stored token.
AI and transcription
- Transcription runs through a speech-to-text provider; generation runs through Vercel AI Gateway on Anthropic's Claude models, with OpenAI models as a fallback.
- Audio is sent to the transcription provider only to produce your transcript. Under Anthropic's and OpenAI's API terms, inputs and outputs aren't used to train their models.
- Pull quotes are checked word for word against your transcript, so we never put invented words in someone's mouth.
Web application
- A strict Content Security Policy, frame blocking and other security headers on every page.
- Sign-out and other state-changing actions require a POST request; redirects after sign-in only go to our own pages.
Reporting a vulnerability
If you find a security issue, email support@afterair.app with the details. Please give us a reasonable chance to fix it before disclosing it publicly. We'll reply within a few working days.