Aurora Corporation · Delaware, United States
Security
Aurora takes a risk-based approach to protecting its services and information entrusted to authorized workflows.
Last updated: September 15, 2026
Principles
- Least privilege and controlled access appropriate to the service.
- Authentication and authorization before protected capabilities are used.
- Secrets protection and separation of production credentials from source code.
- Data minimization and purpose-limited processing.
- Auditability and traceability for governed actions.
- Dependency management and review of relevant provider and software risk.
Operational approach
Controls evolve with the platform and risk. This page does not represent that Aurora holds a specific certification, completed a particular audit, or can guarantee absolute security. Incidents are assessed according to their circumstances, evidence, obligations, and affected systems.
Third-party providers
Aurora uses infrastructure and technology providers for defined functions. Access and processing should be limited to the authorized purpose and reviewed against security, privacy, contractual, and operational needs.
Responsible disclosure
Report a suspected vulnerability to contact@auroraos.online with the subject “Security report.” Include the affected URL or service, reproducible steps, impact, and safe evidence. Do not access other people's data, disrupt services, use social engineering, or disclose an unresolved issue publicly. This is not a bug-bounty offer or authorization for unlawful or harmful activity.