Aurora Corporation · Delaware, United States
Security
Aurora takes a risk-based approach to protecting its services and the information entrusted to authorized workflows.
Security principles
- Least privilege and controlled access appropriate to the service.
- Authentication and authorization before protected capabilities are used.
- Protection of secrets and separation of production credentials from source code.
- Data minimization and purpose-limited processing.
- Auditability and traceability where the workflow requires governed action.
- Dependency management and review of relevant provider and software risk.
Operational approach
Aurora evaluates security measures according to the service, information, provider, and risk involved. Controls evolve with the platform. This page does not represent that Aurora holds a specific certification, has completed a particular audit, or can guarantee absolute security.
Suspected incidents are assessed and handled according to their circumstances, available evidence, applicable obligations, and the affected systems. Aurora does not publish a universal response-time or breach-notification guarantee on this page.
Third-party providers
Aurora uses third-party infrastructure and technology providers for defined functions. Provider access and processing should be limited to the authorized purpose and reviewed in light of security, privacy, contractual, and operational needs.
Responsible disclosure
Report a suspected vulnerability to contact@auroraos.online with the subject “Security report.” Include the affected URL or service, reproducible steps, impact, and safe evidence. Do not access other people’s data, disrupt services, use social engineering, or publicly disclose an unresolved issue.
Aurora will review good-faith reports. This statement is not a bug-bounty offer and does not authorize activity that would otherwise be unlawful or harmful.