Security

Data security practices

Controls used to protect authorized store and customer data.

Infrastructure boundary

Aura’s service node is hosted on AWS in Singapore with a fixed public IPv4 address. Only web traffic on HTTPS and controlled administrative SSH access are exposed. Databases and internal services are not published directly to the internet.

Authentication and authorization

Administrative access requires authentication. Operational access follows role-based access control and minimum-privilege principles. Store data is available only after valid platform authorization.

Encryption and secrets

Public traffic is protected by TLS. Platform credentials, access tokens and application secrets are stored in restricted server configuration and are never included in public website files or client-side code.

Logging and review

Administrative and data access activity is logged where supported. Access rights are reviewed when staff responsibilities change, and access is revoked when no longer required.

Incident response

Suspected security incidents are contained, investigated and documented. Where required by applicable law or platform rules, affected parties and relevant authorities are notified without undue delay.

Data minimization and deletion

We request only permissions needed for the stated operational functions. Data is retained according to our Privacy Policy and deleted or anonymized when no longer required.

Certification statement: We do not claim ISO 27001, SOC 2 or other third-party certification unless a current certification is explicitly published here.