Security at AURE
Protecting your prompts and account is core to how we build. Here's an overview of the controls that safeguard the platform, and how to report a vulnerability if you find one.
Authenticated sessions
Access is protected with signed JWT access + refresh tokens, and refresh tokens rotate on every renewal.
Hashed passwords
Passwords are hashed with bcrypt and a per-password salt — we never store or log them in plain text.
Prompt-injection defense
User text is structurally sanitized so it can't forge trusted instruction markers before reaching a model.
Strict CORS & input limits
Requests are restricted to allow-listed origins, and every payload is schema-validated with size caps.
Rate limiting
Global, per-endpoint, and login/OTP limiters throttle abuse and brute-force attempts.
Safe error handling
Unexpected errors are sanitized to generic responses, and API docs are disabled in production.
Data handling
Your prompts are transmitted over encrypted connections and processed only to deliver the features you request. When a prompt is sent to a third-party AI provider to generate a result, that provider's handling is governed by their own terms. We use the SQLModel/SQLAlchemy ORM with parameterized queries throughout, so user input is never concatenated into raw SQL. See our Privacy Policy for how data is collected and retained.
Accounts & access
Sign-in supports email/password and Google OAuth with server-side token verification. Sessions use short-lived access tokens paired with rotating refresh tokens, and sensitive endpoints such as login and password reset are rate-limited. Forgot-password responses are intentionally uniform to avoid revealing whether an email is registered.
Infrastructure
Secrets are supplied through environment variables, never hard-coded into the application, and production builds reject weak signing keys. Cookies are marked Secure in production, interactive API documentation is disabled, and every request carries a correlation ID for traceable, privacy-respecting logs.
Report a vulnerability
Found a security issue? We appreciate responsible disclosure. Email security@aure.app with details and steps to reproduce. Please give us reasonable time to investigate before any public disclosure — we will acknowledge your report and keep you updated.