Infrastructure boundary
Aura’s service node is hosted on AWS in Singapore with a fixed public IPv4 address. Only web traffic on HTTPS and controlled administrative SSH access are exposed. Databases and internal services are not published directly to the internet.
Authentication and authorization
Administrative access requires authentication. Operational access follows role-based access control and minimum-privilege principles. Store data is available only after valid platform authorization.
Encryption and secrets
Public traffic is protected by TLS. Platform credentials, access tokens and application secrets are stored in restricted server configuration and are never included in public website files or client-side code.
Logging and review
Administrative and data access activity is logged where supported. Access rights are reviewed when staff responsibilities change, and access is revoked when no longer required.
Incident response
Suspected security incidents are contained, investigated and documented. Where required by applicable law or platform rules, affected parties and relevant authorities are notified without undue delay.
Data minimization and deletion
We request only permissions needed for the stated operational functions. Data is retained according to our Privacy Policy and deleted or anonymized when no longer required.