Back to home
SECURITY

Security at AURE

Protecting your prompts and account is core to how we build. Here's an overview of the controls that safeguard the platform, and how to report a vulnerability if you find one.

Authenticated sessions

Access is protected with signed JWT access + refresh tokens, and refresh tokens rotate on every renewal.

Hashed passwords

Passwords are hashed with bcrypt and a per-password salt — we never store or log them in plain text.

Prompt-injection defense

User text is structurally sanitized so it can't forge trusted instruction markers before reaching a model.

Strict CORS & input limits

Requests are restricted to allow-listed origins, and every payload is schema-validated with size caps.

Rate limiting

Global, per-endpoint, and login/OTP limiters throttle abuse and brute-force attempts.

Safe error handling

Unexpected errors are sanitized to generic responses, and API docs are disabled in production.

Data handling

Your prompts are transmitted over encrypted connections and processed only to deliver the features you request. When a prompt is sent to a third-party AI provider to generate a result, that provider's handling is governed by their own terms. We use the SQLModel/SQLAlchemy ORM with parameterized queries throughout, so user input is never concatenated into raw SQL. See our Privacy Policy for how data is collected and retained.

Accounts & access

Sign-in supports email/password and Google OAuth with server-side token verification. Sessions use short-lived access tokens paired with rotating refresh tokens, and sensitive endpoints such as login and password reset are rate-limited. Forgot-password responses are intentionally uniform to avoid revealing whether an email is registered.

Infrastructure

Secrets are supplied through environment variables, never hard-coded into the application, and production builds reject weak signing keys. Cookies are marked Secure in production, interactive API documentation is disabled, and every request carries a correlation ID for traceable, privacy-respecting logs.

Report a vulnerability

Found a security issue? We appreciate responsible disclosure. Email security@aure.app with details and steps to reproduce. Please give us reasonable time to investigate before any public disclosure — we will acknowledge your report and keep you updated.