Security

Your visitor data is sensitive. We treat it that way.

Security and privacy are part of how Aurora is designed, not a layer added afterwards. This page explains how we protect your data, the certifications we hold, and how to reach our security team.

SOC 2 Type II

Audited every year by an independent firm across security, availability and confidentiality. The latest report is available under NDA.

EU or US residency

Choose where your data lives at signup. Visitor data and backups never leave that region.

Encrypted everywhere

TLS 1.2+ in transit, AES-256 at rest, with keys managed in a dedicated key management service.

SSO on every plan

SAML single sign-on for everyone, plus SCIM provisioning and audit logs on Scale.

Infrastructure

Built on hardened, isolated infrastructure.

Aurora runs on Amazon Web Services in regions you choose, with every layer designed to fail safely.

Hosting and regions
Production runs on AWS in Frankfurt (EU) and Oregon (US), each with a failover region in the same jurisdiction. AWS data centers hold SOC 1/2/3, ISO 27001 and PCI DSS certifications.
Network isolation
Services run in private networks with no public access to databases or internal services. Only load balancers are exposed to the internet, behind a web application firewall and DDoS protection.
Tenant isolation
Every query is scoped to a workspace at the data-access layer and enforced again with row-level security in the database, so one customer's data can never be returned for another.
Infrastructure as code
All infrastructure is defined in code, peer-reviewed and deployed through an audited pipeline. Nobody changes production by hand.

Data protection

Encrypted, minimized and yours to remove.

We collect only what's needed to score behavior, protect it at every step, and delete it when you ask.

Encryption
All traffic uses TLS 1.2 or higher with modern ciphers and HSTS. Data at rest — databases, backups and object storage — is encrypted with AES-256. Encryption keys are managed in AWS KMS and rotated annually.
Data minimization
The tracker never records keystrokes, form contents you haven't mapped, passwords or payment data. Full IP addresses are used transiently for location and then truncated before storage.
Backups
Encrypted backups are taken continuously with point-in-time recovery, stored in the same region as your data and retained for 35 days. Restores are tested every quarter.
Deletion
Deleted visitors and workspaces are removed from live systems immediately and from backups within 35 days. See Data & privacy for details.

Application security

Secure development, verified continuously.

Security is part of how we write, review and ship code — not a gate at the end.

Secure development
Every change is peer-reviewed and passes automated tests, static analysis and dependency scanning before it can merge. Engineers complete secure-coding training every year.
Penetration testing
An independent firm tests the application and infrastructure at least once a year and after major releases. Summary reports are available under NDA.
Vulnerability management
Dependencies and container images are scanned daily. Critical vulnerabilities are patched within 72 hours, high-severity within 14 days.
Bug bounty
Security researchers can report issues through our disclosure program, with safe harbor and rewards for valid findings. See below.

Access and monitoring

Least privilege, strong identity, full visibility.

Access to customer data is rare, restricted, logged and reviewed.

Employee access
Engineers have no standing access to production data. Access is granted just in time for a specific support or incident task, approved by a second person, time-limited and logged.
Identity
All employee accounts use single sign-on with hardware security keys. Laptops are centrally managed, encrypted and monitored.
Monitoring and alerting
Infrastructure and application logs feed a central system with automated alerting for suspicious activity, 24/7, with an on-call engineer always available.
Incident response
We maintain and rehearse an incident response plan. If a security incident affects your data, we notify you without undue delay and within 72 hours, with details of what happened and what we're doing about it.

Compliance

Certifications and frameworks.

Documentation for your security review is available on request — most teams get everything they need in one email.

FrameworkStatusWhat it covers
SOC 2 Type IICertifiedSecurity, availability and confidentiality controls, audited annually
GDPR & UK GDPRCompliantDPA with Standard Contractual Clauses and UK Addendum, EU data residency
CCPA / CPRACompliantService-provider terms, no sale or sharing of personal information
ISO 27001In progressCertification audit scheduled; controls already aligned
CAIQ & SIG LiteAvailablePre-filled security questionnaires, on request

Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers and respond quickly. Please give us a reasonable chance to fix an issue before disclosing it publicly.

How to report

Email security@aurora.io with a description of the issue, steps to reproduce it and its potential impact. Encrypt sensitive details with our PGP key, published at aurora.io/.well-known/security.txt.

What to expect

  • Acknowledgement within one business day.
  • An initial assessment and severity rating within five business days.
  • Regular updates until the issue is resolved, and credit in our hall of fame if you'd like it.

Safe harbor

We won't take legal action against research carried out in good faith that respects user privacy, avoids service disruption and data destruction, and only accesses the minimum data needed to demonstrate a vulnerability. Social engineering, physical attacks and denial-of-service testing are out of scope.

Questions we get

What security reviews usually ask.

Do you sell or share visitor data?
No. We never sell or rent visitor data, there are no advertising pixels or data-broker integrations in the tracker, and we only use your data to provide the service to you. This is written into our Data Processing Agreement, not just this page.
Where are your subprocessors listed?
The current list of subprocessors, what each one does and where it processes data is part of the Data Processing Agreement. We give customers at least 30 days' notice before adding a new subprocessor, and you can object.
Can we see your SOC 2 report and pen test results?
Yes. Request them through the contact page and we'll send the latest SOC 2 Type II report and penetration test summary under a standard NDA, usually within one business day.
Can we run our own penetration test?
Yes, on the Scale plan, with two weeks' notice. We'll agree on scope and timing, and provide a dedicated test workspace so your testing doesn't affect production data.
How do you handle data subject requests?
You can export or delete any visitor from the dashboard or the API at any time. Requests you forward to us are handled within 30 days, or sooner if you flag them as urgent. See the Privacy Policy.
What happens to our data if we cancel?
You can export everything at any time. After cancellation, data is retained for 30 days in case you change your mind, then permanently deleted from live systems, and from backups within a further 35 days.
Do you support custom contractual terms?
Scale customers can negotiate security addenda, contractual data residency commitments and custom notification terms. Contact sales to start that conversation.

Have a security questionnaire to complete?

Send it over. Our security team answers most questionnaires within three business days, and we'll share our SOC 2 report under NDA.

security@aurora.io · PGP key in security.txt