PRODSovereign European BaaS platformOpen Dashboard →
Security & Operational Resilience

Security.
By default, everywhere.

Modern encryption, strict isolation, independent audits, public bug bounty. Security is not an add-on — it is our baseline.

#
Six pillars

How we protect your production

Ubiquitous encryption

TLS 1.3 in transit. AES-256 at rest with envelope encryption. BYOK via AWS KMS / HashiCorp Vault on Enterprise plans.

TLS 1.3 · AES-256

Native Postgres RLS

Your access rules live in the database. Testable policies, impossible to bypass on the client side. JWT claims injected by the gateway.

RLS · JWT CLAIMS

Enterprise authentication

SAML 2.0 SSO, SCIM 2.0, configurable enforced MFA, device fingerprint session binding.

SAML · SCIM · MFA

Audits & compliance

Public compliance roadmap (SOC 2, ISO 27001…) on our Trust Center. No third-party certifications engaged to date.

TRUST CENTER →

Public bug bounty

Active program on huntr.dev/aurabase. Bounties from €200 to €10,000 based on severity. 90-day coordinated disclosure policy.

HUNTR.DEV/AURABASE

24/7 monitoring

Internal SOC with documented runbooks. ML-based anomaly detection. PagerDuty alerting, bridge call within 15 min for Sev-1.

24/7 ALERTING
#
Isolation

One database per project, physical isolation between organizations

Unlike platforms that pool customer data into a single table with a tenant_id column, Aurabase gives each project its own Postgres database, with its own connection role: schema permissions are granted only to that role, never to PUBLIC, and the connection is scoped via search_path injected from the JWT at the gateway layer. An application bug cannot leak data from another project.

Between two organizations, isolation goes further and becomes physical: each organization receives its own PostgreSQL cluster, within its own Kubernetes namespace, never shared with another customer. On the Enterprise tier, a project can even run on a fully dedicated cluster of its own — the highest level of isolation we offer.

Info
Each project receives its own database, partitioned into 4 sub-schemas: project_ for your business tables, ..._auth for identity, ..._storage for object metadata, and ..._platform for jobs and secrets.
#
Bug bounty

We pay you to break things

SeverityExamplesBounty
CriticalRCE, root database access, cross-tenant data leak10 000 €
HighSQL injection, auth bypass, privilege escalation3 000 €
MediumStored XSS, CSRF, application DoS800 €
LowInfo disclosure, rate-limit bypass, log injection200 €
Astuce
Program hosted on huntr.dev/aurabase. 90-day coordinated disclosure.
#
Contact

Report a vulnerability

To report a security vulnerability, use our dedicated inbox or our public bug bounty program. We never penalize good-faith security researchers (safe harbor policy).

#
Further reading

Complementary resources

HAVE A SECURITY QUESTION?

Let's discuss it before it becomes critical.

Our security team responds within 24 business hours. For Enterprise requirements, we sign mutual NDAs to share detailed audit reports.

No credit card required · 500 MB free · 50,000 MAU