Home Product Solutions Customers Pricing Changelog About Docs Contact
Aurora Labs Ltd · Shoreditch, London
hello@aurora.io
Home/Security

Security, privacy and the boring details your auditor asks for.

Aurora processes event data for 640+ teams, much of it about their customers. This page is the honest version of how we look after it — the certifications, the sub-processors, the encryption, and what happens on the worst day.

SOC 2 Type II ISO/IEC 27001:2022 UK GDPR & DPA 2018 Cyber Essentials Plus ICO reg. ZB512884
99.98%Platform uptime
15 minSev-1 acknowledgement
2 / yearIndependent pen tests
72 hrsRegulator notification
Certifications

Independently checked,
not self-declared.

Request our report pack

SOC 2 Type II

Audited annually by an independent CPA firm against the Security, Availability and Confidentiality trust services criteria. The most recent report covers a twelve-month observation window ending 31 December 2025 and is available under NDA from security@aurora.io.

ISO/IEC 27001:2022

Certified by a UKAS-accredited certification body, covering the Aurora platform, the supporting cloud infrastructure and the London office. Surveillance audits run annually with full recertification every three years.

UK GDPR & DPA 2018

Aurora Labs Ltd is registered with the Information Commissioner’s Office under number ZB512884. We act as processor for customer event data and as controller for our own account and billing records, and our data processing agreement is available at signature without negotiation for standard terms.

Cyber Essentials Plus

Certified annually, including the hands-on technical audit of workstation patching, malware protection, access control and firewall configuration. Certificates are reissued each June.

PCI DSS

Aurora never stores cardholder data. Billing is handled end to end by our payment processor and we complete SAQ-A each year. If you send us card numbers as event properties, our schema validator rejects them.

Penetration testing

Two independent CREST-accredited tests every year — one full-scope application test and one infrastructure and cloud configuration review — plus a targeted test before any major architectural change ships.

Encryption

Encrypted in transit, encrypted at rest.

Every connection to Aurora is TLS 1.3 with forward secrecy. TLS 1.2 remains available for legacy server SDKs and everything older is refused outright; HSTS is enabled with preload, and our certificates are issued with a 90-day lifetime and rotated automatically.

  • AES-256 at rest across databases, object storage and backups, with keys held in AWS KMS
  • Per-workspace data keys, rotated annually and immediately on request after an offboarding
  • Field-level encryption for properties flagged as personal data in your event catalogue
  • Application secrets in HashiCorp Vault with short-lived dynamic database credentials
  • No production data in development or staging environments, ever — seeded fixtures only
Data residency

London by default, Frankfurt on request.

New workspaces are provisioned in AWS eu-west-2 (London) and stay there. Enterprise customers who need EU-only processing can be pinned to eu-central-1 (Frankfurt) at provisioning time; the choice is made once and cannot drift afterwards.

  • Event data, backups and derived tables never leave the region you chose
  • Support access is region-aware — a London-based engineer cannot read Frankfurt data without an approved, logged, time-boxed grant
  • Where any transfer is unavoidable, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, with a transfer risk assessment on file
  • Aggregated, non-identifying platform telemetry is the only thing that crosses regions
Sub-processors

Everyone who touches the data.

Sub-processorPurposeProcessing location
Amazon Web Services EMEA SARLCloud hosting, storage, managed databasesLondon (eu-west-2), Frankfurt (eu-central-1)
Cloudflare LtdCDN, DDoS mitigation, web application firewallEU edge network, no origin storage
Datadog EUInfrastructure monitoring, application logs, alertingFrankfurt, Germany
Twilio SendGridTransactional email — alerts, reports, account noticesDublin, Ireland
Zendesk International LtdCustomer support ticketing and knowledge baseDublin, Ireland
Stripe Payments Europe LtdSubscription billing and payment processingDublin, Ireland
Slack Technologies LtdShared support channels for Enterprise customersEU region, Enterprise Grid
Snowflake Computing Netherlands B.V.Optional warehouse destination, provisioned only at customer directionFrankfurt, Germany

We give 30 days’ written notice before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds. To be added to the notification list, email security@aurora.io. The current list is also annexed to our data processing agreement — see the privacy notice for the full picture.

Retention

How long we keep things.

DataDefault retentionNotes
Raw event data30 days (Starter) · 13 months (Growth) · configurable (Enterprise)Deleted from live storage and from backups on the next rotation.
Identified user profilesLifetime of the workspaceErasable per subject on request; propagates to synced warehouses.
Aggregated metrics25 monthsNon-reversible aggregates retained for year-on-year comparison.
Audit logs13 months (up to 7 years on Enterprise)Immutable, exportable to your SIEM via the audit log API.
Encrypted backups35 daysPoint-in-time recovery within the same region; never replicated outside it.
Support correspondence24 monthsHeld in Zendesk under our own controller obligations.
Closed workspacesPurged 30 days after terminationExtended only where you ask us in writing to hold data for migration.

Erasure requests from your end users are actioned through the API or the dashboard and complete within 30 days, including in downstream warehouse destinations we sync to. Deletion is real deletion, not a hidden flag on a row.

Access control

Who can see what.

  • SAML 2.0 and OIDC single sign-on with Okta, Microsoft Entra ID, Google Workspace and any compliant IdP
  • SCIM 2.0 provisioning — joiners, movers and leavers sync automatically, and deprovisioning revokes sessions immediately
  • Role-based access control down to column level, so a support role can read usage without ever seeing revenue
  • Enforced MFA for every Aurora employee, backed by hardware security keys with no SMS fallback
  • No standing production access for staff — access is requested, approved by a second person, time-boxed and logged
  • Quarterly access reviews across production, the corporate estate and every third-party tool
  • Immutable audit logs of every login, permission change, query and export, streamable to your SIEM
  • Background checks and annual security training for all staff, with role-specific secure development training for engineers
Testing

Two pen tests a year, and continuous scanning in between.

A CREST-accredited firm tests the full application surface every spring and the cloud and network estate every autumn, with an additional targeted engagement before any significant architectural change. Summary letters are available under NDA; findings are tracked to closure with critical issues fixed inside seven days.

  • Static analysis and dependency scanning on every pull request, blocking merge on a critical finding
  • Weekly authenticated dynamic scans against a production-equivalent environment
  • A private bug bounty programme with rewards from £250 to £8,000 depending on severity
Disclosure

Found something? Tell us.

Report anything you believe affects the security of Aurora to security@aurora.io. We acknowledge within one working day, give you a triage decision within three, and keep you updated until it is closed. Our PGP key and policy are published at /.well-known/security.txt on aurora.io.

AcknowledgeWithin 1 working day of your report landing
TriageSeverity and remediation plan within 3 working days
Safe harbourWe will not pursue legal action for good-faith research that respects this policy
Out of scopeDenial-of-service testing, social engineering of our staff, physical attacks on the Paul Street office, and anything touching another customer’s data
Incident response

What happens on the worst day.

01

Detect

Continuous monitoring, anomaly detection on our own platform and a 24/7 on-call rotation. Severity 1 incidents are acknowledged within fifteen minutes, at any hour, by a named engineer.

02

Contain

The on-call engineer has standing authority to isolate a component, revoke credentials or fail a region over without waiting for a manager. Containment comes before root cause, every time.

03

Notify

Affected customers are told without undue delay through the status page and a direct message to your named security contact. Where a personal data breach is notifiable, we report to the ICO within 72 hours under Article 33 of the UK GDPR and support your own notification obligations.

04

Remediate

A fix ships, then the class of problem gets closed off — a monitor, a test, or an architectural change — before the incident is considered resolved.

05

Review

A blameless post-incident review is written up and shared with affected customers within ten working days, including timeline, impact and the specific commitments we have made.


Contact

Security questionnaires and DPAs.

Send vendor security questionnaires, data processing agreements and audit requests to our security team and you will get a completed response, not a link to a portal. Our Data Protection Officer can be reached at the same address.

Aurora Labs Ltd · Registered in England 09417732
86–90 Paul Street, Shoreditch, London EC2A 4NE

security@aurora.io — vulnerabilities, questionnaires, reports
privacy@aurora.io — data protection and subject rights
020 7946 0170
The paperwork

Policies in full.

Need the report pack
before you can buy?

Tell us which questionnaire you are working through and we will send the SOC 2 report, ISO certificate and DPA the same day.