Trust & security
Aura runs two trust contexts on one engine. Consumers own their own data. Institutions operate inside a workspace built for FERPA-governed deployments — with SSO, database-level tenant isolation, audit logging, and per-tenant data controls.
We describe what is in place honestly. Aura provides FERPA-ready controls for institutions acting as the school official; it is not a claim of certification. Status reflects current availability.
Identity & access
Single sign-on (SAML 2.0)
AvailableInstitutional users authenticate through your own identity provider. Email/OTP remains for direct consumers.
Verified institutional identity
AvailableFor institution records, identity comes from the verified SSO assertion — never a user-typed email.
Advisor–student consent links
AvailableAdvisors see a student's record only after the student approves the link; access is scoped to consented students.
Role-based access (RBAC) & admin console
In progressStudent / advisor / department / org-admin roles and a provisioning console for institution administrators.
Data isolation & governance
Database-level tenant isolation
AvailableEvery institution record is bound to an organization id and isolated by Postgres row-level-security policies — enforced in the database, not just application code.
Record provenance
AvailableEach record is stamped consumer vs institution, and with how the user authenticated, so institutional data is unambiguous.
Tenant audit trail
AvailableAccess and changes to institution records (e.g. an advisor opening a student record) are recorded per tenant.
Admin-visible audit views
In progressSurfacing the audit trail to institution administrators (the 'who accessed what' view).
Data rights & retention
Per-person data deletion
AvailableAtomic deletion of an individual's data across all tables on request.
Configurable retention & AI limits
AvailablePer-tenant retention windows and AI usage caps are configurable at the organization level.
Self-serve export & correction
In progressInstitution-facing workflows for data export and record correction.
Security
Deny-by-default data access
AvailableRow-level security is enabled deny-by-default on all tables; privileged access is server-side only.
Rate limiting & spend controls
AvailablePer-IP and per-account rate limits, plus a global AI spend circuit-breaker with admin alerting.
Dependency & error monitoring
AvailableCI blocks high/critical dependency advisories; runtime errors are tracked and alerted.
Third-party penetration test
PlannedAn independent penetration test ahead of broad institutional rollout.
Accessibility
WCAG 2.1 AA conformance
In progressSkip links, focus states, semantic landmarks, reduced-motion, and non-color indicators are in place; continuous automated testing and a VPAT are being finalized.
For procurement
A Data Processing Agreement, school-official terms, and a completed HECVAT-Lite are available to institutional reviewers on request. The pilot onboarding process configures SSO, tenant binding, and retention for your institution.
Documents
Security or privacy questions? privacy@useaura.net