What we see
Only the Pull Request diff and the repository context needed to evaluate it. Never the full repository. AURA human reviewers are not in the flow: processing is automatic.
The questions a CTO or CISO asks before connecting their code, answered without hedging: what we see, where it is processed, how long it is retained, who accesses it, and what we do not promise yet.
Only the Pull Request diff and the repository context needed to evaluate it. Never the full repository. AURA human reviewers are not in the flow: processing is automatic.
Code is processed ephemerally and is not stored after review. We keep findings, verdicts, and metadata for your history and reports. Zero use for model training, by contract.
Each organization has its own GitHub App credentials and separated data. Admin, Reviewer, and Observer roles. An audit log of every access, exportable.
Signed webhooks (HMAC), rate limiting, encryption in transit and at rest, monitoring with Sentry, documented daily backups. WebAuthn authentication available.
Automatic routing across three model tiers. On Enterprise you choose the provider, restrict the geographic processing region, or bring your own API key: your code goes to the provider you choose, under your own contract.
Runtime runs locally and links to the web with a pairing code and a remote approval window with expiry (12 or 24 hours). Without that active link, no one can approve actions on your machine from outside.
View Runtime metadata →Secret detection, injection patterns, personal data in logs, and continuous monitoring of vulnerable dependencies with Dependabot. All inside the security criterion of every verdict.
CVEs matched against your real dependencies with same-day publication alerts, suggested remediation PR, full-repository review, and confirmation of each finding before it is shown. SOC 2 Type I: target Q4 2027.
Attacking an isolated instance of the code before merge (load, injection) and deployment on your own infrastructure. They are in our product vision. We do not put a date on them until they exist in alpha: we prefer not to promise what we cannot yet deliver.
Every customer can sign a Data Processing Agreement (DPA) that includes: ephemeral code processing, zero retention after review, explicit prohibition of use for model training, right to audit access logs for their organization, incident notification within 72 hours, and an exit clause with full export of configuration and history. Request it at legal@aura-control.com.
AURA uses infrastructure and AI model providers to operate. The current list of subprocessors, with their function, location, and retention policy, is published and updated on this page; Enterprise customers receive prior notice of any change. On the Enterprise plan, the customer defines the model provider and region.
| Category | Function | Note |
|---|---|---|
| Infrastructure and database | Platform hosting, queues, backups | Encryption in transit and at rest |
| AI model providers | Diff analysis and spec generation | No retention for training; selectable by the customer on Enterprise |
| Payments | Stripe, Mercado Pago, OrbiPay | AURA does not store card data |
| Error monitoring | Sentry | No customer source code in events |
| Transactional email | Notifications and lifecycle | Email and account metadata only |
If you find a vulnerability in AURA, write to us at security@aura-control.com. We confirm receipt within 48 hours, take no legal action against good-faith research, and publicly acknowledge reporters who wish it.
The service is provided by AURA. Legal entity details appear only in the site legal notice and in the contracts you sign.
Connect your repository and get your first verdict in under ten minutes. No card, no sales call, no change to your workflow.
“Whoever decides doesn't compete in the game.” — Our neutrality commitment