Security

Your billing data, handled with care.

Aura Plus connects to some of the most sensitive data your organization has — cloud cost, usage, and account metadata. Protecting it is foundational to the platform, not an afterthought.

Note for the Aura Plus team: this page is a professionally structured template. Every claim below must be verified against what Aura Plus actually implements before publishing. Do not state a certification (SOC 2, ISO 27001, etc.) as complete unless the report is in hand. Placeholders are marked [confirm].

Our approach

We design for least privilege, encrypt data in transit and at rest, and log every action taken in the platform. Access to customer data is restricted, role-based, and auditable.

Data protection

  • Encryption in transit: all traffic served over TLS [confirm version/config].
  • Encryption at rest: customer data encrypted at rest using [confirm cipher/KMS].
  • Data residency: data stored in [confirm region/provider].
  • Retention & deletion: [confirm retention window and deletion process].

Access controls

  • Role-based access control (RBAC) across all platform actions
  • Full audit log of automated and human actions, including every recovery claim
  • Single sign-on (SSO) support [confirm: SAML/OIDC availability]
  • Principle of least privilege for internal staff access [confirm]

Cloud connections

Aura Plus connects to your cloud accounts using scoped, read-oriented permissions wherever possible. Recovery actions that write or file claims are gated behind explicit human approval. [Confirm the exact permission model and scopes per provider.]

Compliance

[Confirm before publishing.] State only frameworks you can substantiate. If a SOC 2 Type II effort is in progress, describe it accurately as "in progress" with a target — do not imply completion. Offer to share reports under NDA on request.

Reporting a vulnerability

We welcome responsible disclosure. If you believe you've found a security issue, contact us at security@myfinops.org [confirm address]. Please include steps to reproduce and allow us reasonable time to respond before public disclosure.

For a security review during evaluation, our team will walk through data handling, retention, and compliance specifics tailored to your requirements. Request a demo to start that conversation.

Questions from your security team?

We're happy to walk through the details before you connect a single account.

Talk to us