Aristotto.ai
Aristotto
  • Home
  • Pricing
  • Blog
HomeAssets
Image Upscaler
Studio HubMarketing StudioWorkflowsVideo EditorMCP
TemplatesVideo EffectsPhoto Effects
Community

Security Policy

Last updated: September 30, 2026~6 min read

This policy describes security responsibilities when using Aristotto and the scope of security information provided here. Protect your credentials, review connected apps before authorizing them and report suspected compromise promptly. Authorized processing and the visibility selected for content affect who can access it. No service can guarantee complete prevention of incidents.

Report a suspected vulnerability to support@aristotto.ai, with the affected feature, reproduction steps and enough information to understand the concern. Do not include another user's private information or a live secret. A report does not authorize intrusive testing, disruption or access to someone else's account, and this policy does not offer a bug-bounty payment or a guaranteed response deadline.

Data SecurityVulnerability ManagementOps SecurityCompliance

On this page

  • Data Security
  • Encryption
  • Network Security
  • Vulnerability Management
  • Penetration Testing
  • Change Management
  • Cybersecurity Awareness
  • DDoS Prevention
  • Ops Security
  • Physical Security
  • Device Security
  • Intrusion Detection and Prevention
  • Data Isolation
  • Compliance

Aristotto applies access restrictions and service safeguards appropriate to its operation. Account and workspace permissions, content visibility and authorized provider processing are distinct: private visibility does not mean that information is never processed by a provider needed for the requested feature. Share content only with the people and apps you intend to authorize.

Security decisions should consider the sensitivity and purpose of information and limit access to the relevant task. Do not place passwords, financial credentials or unnecessary sensitive records in prompts, public posts or support messages. Administrative access does not grant permission to use content for unrelated promotion or model training.

Encryption in transit, encryption of stored data and access permissions address different risks. A secure browser connection alone does not establish that every stored copy uses the same encryption, that every provider follows identical practices, or that a service offering is end-to-end encrypted.

Use the service's official secure URLs and keep your browser current. Do not transmit credentials through untrusted links or include them in an upload. This policy does not promise a particular cipher, protocol version, key-management system or complete encryption of every provider's data.

Do not bypass access restrictions, scan another user's resources, extract credentials, introduce malicious traffic or interfere with the service. A feature's public URL does not authorize access beyond the permissions granted for it.

Network protections and authentication are part of a broader security approach, rather than a guarantee that a request is harmless merely because it reaches the service. Third-party processing and connected apps introduce their own access boundaries. Report an unexpected access path instead of exploiting it.

Report reproducible weaknesses through the security contact and provide the affected page or feature and the steps needed to understand the issue. Redact secrets and unrelated personal information. If you encounter someone else's information, stop accessing it and describe the exposure without copying more than is necessary to report the concern.

Security reports need assessment according to impact and affected systems. This policy does not assert that every report is a vulnerability or promise a fixed repair schedule, scanning frequency or automated prevention of every class of issue.

Submitting a report is not permission to conduct penetration testing against the service or its suppliers. Obtain explicit authorization before testing beyond ordinary permitted use. Do not disrupt availability, attempt persistence, obtain other users' information or test a third-party system without its owner's permission.

This policy does not claim an annual external penetration test, an independent assessment or certification. A security review has a defined scope and time; it cannot establish that every feature and later change is free from vulnerabilities.

Changes to a service can affect access, processing and security. Policy changes that add processing permissions remain subject to the Terms, privacy requirements and any required notice or consent. A technical change does not itself create permission to train on content or use it for unrelated promotion.

Keep client software current and review notices relevant to the features you use. This policy does not guarantee a particular deployment workflow, test coverage or an uninterrupted rollout of every update.

Be cautious of phishing, unexpected payment requests and messages asking for a password, token or remote access. Verify that you are using the official service and review the identity and requested scopes of a connected app before approving it. Report suspected impersonation or account compromise.

Do not share access in violation of plan limits or use another person's credentials. Anyone handling service information should respect confidentiality and authorized purposes. This policy does not describe an unverified staff training program or certify the conduct of every supplier.

Do not flood requests, overload a feature, automate abusive traffic or organize activity intended to disrupt access. Authorized workflows and connected-app requests remain subject to their scopes, queues and usage limits.

Availability can be affected by malicious traffic, capacity, connectivity and provider outages. Abuse restrictions help protect shared service capacity, but this policy does not promise a specified DDoS mitigation provider, unlimited resilience or uninterrupted service.

Account access and connected-app permission should be limited to authorized use. Review active connections and remove access you no longer need. Notify support promptly if you suspect unauthorized activity and keep the account's contact information current.

An account restriction, access revocation, content deletion and subscription cancellation have different effects. Revocation does not recall information already received by a third party. Operational and legal records can remain subject to the retention rules in the Privacy Policy.

Hosting and storage can depend on third-party facilities and infrastructure. Their physical safeguards and locations are distinct from Aristotto's account and workspace access controls. Private content visibility does not identify a storage facility or establish a particular physical-security certification.

Protect devices and places where you access the service, especially shared workstations. Sign out where appropriate and avoid leaving an authenticated session available to another person. This policy does not claim ownership of data centers or a specific provider audit status.

Use a supported, current browser and keep your device's operating system and security software current. Protect the device's screen and account access, and use care when downloading media or opening links received from other users. Browser extensions and locally installed apps can have access independent of Aristotto.

Losing a device or authorizing an app can expose information even where a service uses secure connections. This policy does not claim that every employee or user device is enrolled in a particular management program or uses a specified encryption configuration.

Security and moderation records can support investigation of suspicious access, abuse and attempts to evade an account restriction. Activity should not be interpreted as authorized merely because no immediate alert or block appears.

Report suspected intrusion or unintended access promptly. Do not attempt to bypass detection or interfere with records. This policy does not promise a named firewall, continuous detection of every intrusion or a particular automated-response capability.

Public content, private personal content and team content have different visibility. Team access follows the workspace and its authorized participants; connected apps receive information within their authorized scopes. A plan or request setting must be reviewed before submitting sensitive material.

Logical access restrictions are distinct from dedicated physical infrastructure or a guarantee that a processor never handles content. This policy does not promise a separate server or database for every account. Contact support if information appears available outside the access you intended.

Security, privacy and copyright obligations depend on the operation, applicable law and contractual commitments. A designated copyright agent is one part of the copyright process, rather than a security certification or automatic immunity for every claim. Security safeguards do not replace required privacy notices, consent or content permissions.

No external certification, audit report, compliance badge or whole-platform standard is asserted by this policy. Request information relevant to your particular use through the support or legal channel. Mandatory rights and remedies remain subject to applicable law.

Aristotto.ai

The unified AI creative canvas. Every frontier model, one prompt away, under a single subscription.

Product
  • AI Video
  • AI Image
  • Video Effects
  • Photo Effects
  • Workspace
  • Community
  • MCP
  • Workflows
  • Marketing Studio
  • Video Studio
  • Audio Studio
  • Models
Models
  • Gemini Omni Flash 1.1
  • FLUX 3
  • Wan 3.0
  • MiniMax H3
  • Seedance 2.5
  • Grok Imagine Video 1.5
  • GPT Image 2.5
  • Recraft 4.1
  • Nano Banana 2
Resources
  • Blog
  • Pricing
  • FAQ
  • Official News
  • Rewards Center
  • Help Center
  • Affiliates
Company
  • About
  • Enterprise
  • Contact
ARISTOTTO.AI
© 2026 ARISTOTTO.AI
Terms of UsePrivacy PolicyInternet-Based AdvertisingCommunity GuidelinesDMCASecurity PolicyAccessibilityYour Privacy Choices

Reward Center

Daily Rewards

Daily Streak

Login every day to earn credits!

Day 1
20
Day 2
30
x2Day 3
80
Day 4
50
Day 5
60
x2Day 6
160
x3Day 7
450
Sign in to start claiming daily credits

One-time Rewards

0%

Customize your profile

Upload avatar & banner to earn credits

Upload avatarUpload banner
+150
Complete Profile