Aura Plus connects to some of the most sensitive data your organization has — cloud cost, usage, and account metadata. Protecting it is foundational to the platform, not an afterthought.
We design for least privilege, encrypt data in transit and at rest, and log every action taken in the platform. Access to customer data is restricted, role-based, and auditable.
Aura Plus connects to your cloud accounts using scoped, read-oriented permissions wherever possible. Recovery actions that write or file claims are gated behind explicit human approval. [Confirm the exact permission model and scopes per provider.]
[Confirm before publishing.] State only frameworks you can substantiate. If a SOC 2 Type II effort is in progress, describe it accurately as "in progress" with a target — do not imply completion. Offer to share reports under NDA on request.
We welcome responsible disclosure. If you believe you've found a security issue, contact us at security@myfinops.org [confirm address]. Please include steps to reproduce and allow us reasonable time to respond before public disclosure.
We're happy to walk through the details before you connect a single account.
Talk to us