Trust & Safety

Security & Privacy

Aura AI is built local-first. Your source code, design docs, chats, and project memory stay under your control, and your content is not used for training.

Our commitments

🚫

No training on your content

Your source code, design docs, prompts, and project context are not used for model training. Aura is built for commercial projects where unreleased mechanics, lore, and production plans need to stay yours.

Security

TLS in transit

Account, billing, update, diagnostic, and model-request traffic is encrypted in transit. Local engine communication stays on your machine.

Report

Sanitized error reports

Automatic reports are bounded to technical metadata and sanitized stack frames. They exclude prompts, projects, GDDs, keys, payment data, balances, and absolute paths, and are available only in the founder-authenticated support queue.

🔑

Authentication secured

Authentication uses signed JWTs. User sessions are validated server-side and scoped to the authenticated account to enforce account-specific access.

🛡️

No data sold to third parties

We do not sell or rent your usage data, code context, or personal information to advertisers or data brokers. Service providers receive only the data needed to provide the selected feature.

Local

Hub runs locally

Aura AI is a native background service that runs on your machine. Project context, GDDs, pages, rules, chats, and project memory are local-first and do not sync to a cloud workspace by default.

🗄️

Account data isolation controls

Server-side authorization, row-level security, role checks, and fail-closed gates separate account, subscription, wallet, organization, and support data. Security reports remain subject to ongoing testing and independent review.

What goes where

A transparent breakdown of every data type Aura touches, where it goes, and who can access it.

Swipe sideways to compare where each data type goes and who can access it.

Data Type Where It Goes Who Can See It
AI Prompts & Code Context Sent as necessary request context to the model provider and funding route you selected The selected provider processes the request; Aura does not use it for training
Project files, GDDs & context Local by default. Pro sync or a Cloud Loop uses encrypted cloud storage or isolated cloud processing only after you enable it. You and the Aura services needed to provide the cloud feature you enabled; never used for training
Billing and wallet data Remote database (RLS-protected) You only; Aura backend for software entitlement and wallet reservation/settlement
Email Address Auth provider; Resend for transactional email Aura account operations and the service providers needed for authentication and email delivery
Payment Information Stripe (we never see raw card data) Stripe only
Error reports Private support storage after strict client and server allowlist checks Founder-authenticated Aura support only; never includes prompts, project content, credentials, payment data, balances, or absolute paths
Website analytics Limited public-page, referral, campaign, tutorial, navigation, and engagement events sent to Google Analytics Aura and Google Analytics for aggregate website measurement; events exclude prompts, project content, provider keys, payment details, and wallet balances
Chat History Local by default; encrypted multi-device continuity is available only when a Pro user enables cloud sync You; Aura's cloud service handles encrypted synchronization only when enabled
Issue

Responsible Disclosure

Found a security vulnerability? Please report it. We review reports as promptly as possible and will work with you to investigate and resolve confirmed issues responsibly.

security@aurainc.co

We don't run a formal bug bounty program, but we will acknowledge your contribution publicly if you'd like.

Compliance status

This page describes current product controls. It is not a certification or a substitute for your organization’s legal or security review.

📋

SOC 2

Aura is not currently SOC 2 certified. Do not treat product architecture or internal testing as certification.

Not certified
🇪🇺

Privacy requests

Account data export and deletion requests are handled through the published privacy process. Independent legal review remains separate from product testing.

Process available
🔒

Independent review

Independent professional security, legal, and tax reviews remain explicit external follow-ups. Aura does not claim they are complete.

External follow-up