All policies

Security

Effective August 1, 2026

Aurora is the system of record for your customer relationships, support conversations, and campaigns — we treat the security of that data as core product functionality, not an afterthought.

Infrastructure & data protection

All customer data is stored in isolated, tenant-scoped MongoDB Atlas clusters with encryption at rest (AES-256) and in transit (TLS 1.2+) for every connection, including API calls, email/WhatsApp channel sync, and internal service-to-service traffic.

Application infrastructure runs on hardened, regularly patched cloud infrastructure with network-level isolation between environments. Production access is restricted to a small set of engineers and is logged.

Authentication & access control

Aurora issues short-lived, revocable session tokens (JWTs bound to a session record) rather than long-lived static tokens, so a compromised device can be signed out remotely from Settings → Security.

Role-based permissions govern what each user in your organization can see and do, down to individual modules (CRM, Help Desk, Analytics, Billing) and record-level ownership.

Monitoring & incident response

Login events, session activity, and sensitive account changes are recorded in an audit log visible to admins under Account Activity.

We maintain an internal incident-response process for triaging and remediating security issues. If an incident affects your data, we will notify affected organizations without undue delay once impact is confirmed.

Responsible disclosure

If you believe you’ve found a security vulnerability in Aurora, please report it to security@aurora.com with enough detail to reproduce the issue. We ask that you avoid accessing or modifying other customers’ data and give us a reasonable window to investigate and remediate before public disclosure. We do not pursue legal action against good-faith researchers who follow this process.

Questions about this policy? Contact us.