Security.
By default, everywhere.
Modern encryption, strict isolation, independent audits, public bug bounty. Security is not an add-on — it is our baseline.
How we protect your production
One database per project, physical isolation between organizations
Unlike platforms that pool customer data into a single table with a tenant_id column, Aurabase gives each project its own Postgres database, with its own connection role: schema permissions are granted only to that role, never to PUBLIC, and the connection is scoped via search_path injected from the JWT at the gateway layer. An application bug cannot leak data from another project.
Between two organizations, isolation goes further and becomes physical: each organization receives its own PostgreSQL cluster, within its own Kubernetes namespace, never shared with another customer. On the Enterprise tier, a project can even run on a fully dedicated cluster of its own — the highest level of isolation we offer.
project_ for your business tables, ..._auth for identity, ..._storage for object metadata, and ..._platform for jobs and secrets.We pay you to break things
huntr.dev/aurabase. 90-day coordinated disclosure.Report a vulnerability
To report a security vulnerability, use our dedicated inbox or our public bug bounty program. We never penalize good-faith security researchers (safe harbor policy).