The web application and serverless functions are deployed through Vercel. Application data is stored in Neon Postgres. Production traffic is served over HTTPS with long-duration HSTS enabled.
Customer queries and mutations are scoped server-side to the authenticated organization. Role requirements are enforced by the server for privileged customer actions.
Customer access uses time-limited login tokens and host-prefixed, Secure, HttpOnly, SameSite=Strict session cookies. Login and session tokens are stored as hashes rather than reusable plaintext values.
Customer application pages use no-store caching, restricted framing, content-type protection, same-origin referrer handling, limited browser permissions and a Content Security Policy.
The public demo uses fictional companies and sample assessments. It is isolated from customer login and is not intended for customer-confidential documents or compliance decisions.
The public site uses Google Analytics. Access requests may collect name, work email, company, approximate entity count, product interest and attribution as described in the privacy policy.
Information is retained as reasonably necessary to operate the service, meet legal obligations and protect the platform. Access, correction and deletion requests can be directed to the contact below.
Report a suspected security issue privately to greg@aurorumventures.com. Do not include passwords, tokens or sensitive customer records in the initial message.
Evaluate the controls and the operating method together.
Review how monitored sources, retained versions, human review and failure visibility are represented before requesting access.
Read the methodology →Privacy policy