Skip to content

Security built into
the foundation.

These are the controls protecting your Aurora account right now. Each one is running today; this page is not a roadmap.

Encrypted connections
HTTPS connections to Aurora are encrypted with TLS. Current browsers connect with TLS 1.3 or TLS 1.2.
Sign-in
One Aurora account signs you in to every app with your email and password. Passwords are hashed with bcrypt and never stored in readable form, and repeated sign-in, sign-up and reset attempts are throttled.
Sessions and reset links
Your session is kept in an HttpOnly cookie that is only sent over HTTPS. Password reset links are stored hashed, expire after one hour and work only once.
Security notices
Changing your password in your account settings, or resetting it with an emailed link, sends a notice to your email address. When your account email changes, both the old and the new address are told.
Payments
Checkout and card updates happen on pages hosted by Stripe. Your card number never reaches Aurora’s servers.
Backups
Encrypted backups run every night. Once a week an automated test restores them into a separate database to prove they can be read back.

Engineering practices

  • Our sites and apps are published through a Cloudflare tunnel
  • Payment webhooks are verified by signature before anything is recorded
  • After sign-in, redirects to outside websites are refused
  • Google and GitHub connections use a signed state check, and disconnecting deletes the stored tokens
  • One account cannot read another account’s billing

Email support on every plan

Every plan, Free included, gets the same email support. Tell us what happened and we’ll reply by email.

Sub-processors

These companies may process data on Aurora’s behalf. The subprocessor register also lists what data reaches each one and where it is located.

Anthropic
AI model that generates chat and assistant responses
Stripe
Payment processing, subscriptions, and invoicing
Cloudflare
DNS, network delivery, TLS termination, denial-of-service protection, determining the approximate country of each sign-in from your IP address for sign-in security, and cookieless page analytics, only if you allow the Analytics category
Resend
Transactional email — account verification and password reset links, receipts, and account notices
Google
Connecting your Google account, and the Google services you explicitly authorise
Open-Meteo
Weather for the dashboard weather card, and city search when you choose a place
OpenStreetMap Foundation (Nominatim)
Turning your location into a city name when you choose Use my location on the weather card
GitHub
Optional GitHub connection for repository features

Questions about security?

Write to our security team with your questions about these controls, or send us your security questionnaire.

Contact our security team