Security

Clear boundaries before broader automation.

AuraMind uses practical security and human-approval controls appropriate to each workflow. This page describes an approach, not a certification or guarantee.

Access

Least necessary scope

Start with the minimum data, tool permissions and environments needed to reproduce or build the workflow.

Action

Human gates

Keep approval around financial, legal, safety-sensitive, identity-bearing or otherwise high-impact actions.

Evidence

Inspectability

Record the inputs, tool calls, outputs and decision state needed to investigate failure without exposing unnecessary private data.

Public website

Current technical controls.

  • HTTPS and transport security through the hosting platform.
  • Content-type, referrer and browser-permission policy headers.
  • Microphone, camera and geolocation disabled on the AuraMind root site.
  • Form honeypot and provider-side submission handling.
  • Content Security Policy introduced in report-only mode for testing.

Third-party product sandboxes have their own runtime and provider dependencies. They require separate review before production use.

Report an issue

Share the minimum needed to reproduce.

Email contact@aura-mind.de with the affected URL, observed behavior, impact and safe reproduction steps. Do not include active credentials, sensitive personal data or exploit other users' data.

AuraMind does not currently claim ISO, SOC 2 or other security certification.