All policies

Compliance

Effective August 1, 2026

Aurora is built to help regulated and privacy-conscious businesses run their customer operations without compromising on compliance. This page summarizes the frameworks we align with; specific certifications and reports are available under NDA on request.

Data protection frameworks

Aurora’s data handling practices are designed to align with the EU General Data Privacy Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and equivalent data-protection regimes in the markets our customers operate in — see our GDPR Compliance page for GDPR-specific detail.

Sub-processors

Aurora relies on a limited set of sub-processors for infrastructure (cloud hosting, database, transactional email/SMS, payment processing) — each is contractually bound to data-protection terms at least as strict as our own. A current sub-processor list is available on request from privacy@aurora.com.

Data residency

By default, customer data is hosted in the region your organization is provisioned in. Enterprise customers with specific data-residency requirements should contact sales@aurora.com to discuss available regions.

Audits & reports

We undergo periodic third-party security assessments. Enterprise customers can request our latest security questionnaire, penetration test summary, and (where applicable) SOC 2 report status through their account team.

Questions about this policy? Contact us.