SOC 2 Type II
Audited every year by an independent firm across security, availability and confidentiality. The latest report is available under NDA.
Security
Security and privacy are part of how Aurora is designed, not a layer added afterwards. This page explains how we protect your data, the certifications we hold, and how to reach our security team.
Audited every year by an independent firm across security, availability and confidentiality. The latest report is available under NDA.
Choose where your data lives at signup. Visitor data and backups never leave that region.
TLS 1.2+ in transit, AES-256 at rest, with keys managed in a dedicated key management service.
SAML single sign-on for everyone, plus SCIM provisioning and audit logs on Scale.
Infrastructure
Aurora runs on Amazon Web Services in regions you choose, with every layer designed to fail safely.
Data protection
We collect only what's needed to score behavior, protect it at every step, and delete it when you ask.
Application security
Security is part of how we write, review and ship code — not a gate at the end.
Access and monitoring
Access to customer data is rare, restricted, logged and reviewed.
Compliance
Documentation for your security review is available on request — most teams get everything they need in one email.
| Framework | Status | What it covers |
|---|---|---|
| SOC 2 Type II | Certified | Security, availability and confidentiality controls, audited annually |
| GDPR & UK GDPR | Compliant | DPA with Standard Contractual Clauses and UK Addendum, EU data residency |
| CCPA / CPRA | Compliant | Service-provider terms, no sale or sharing of personal information |
| ISO 27001 | In progress | Certification audit scheduled; controls already aligned |
| CAIQ & SIG Lite | Available | Pre-filled security questionnaires, on request |
Responsible disclosure
We welcome reports from security researchers and respond quickly. Please give us a reasonable chance to fix an issue before disclosing it publicly.
Email security@aurora.io with a description of the issue, steps to reproduce it and its potential impact. Encrypt sensitive details with our PGP key, published at aurora.io/.well-known/security.txt.
We won't take legal action against research carried out in good faith that respects user privacy, avoids service disruption and data destruction, and only accesses the minimum data needed to demonstrate a vulnerability. Social engineering, physical attacks and denial-of-service testing are out of scope.
Questions we get
Send it over. Our security team answers most questionnaires within three business days, and we'll share our SOC 2 report under NDA.
security@aurora.io · PGP key in security.txt