How to report
Email support@parathoughtlabs.com with “Aura security report” in the subject. Include the affected URL or component, impact, reproducible steps, and any supporting request or response details. Remove passwords, access tokens, payment information, and personal data that are not essential to the report.
We will acknowledge a credible report as soon as reasonably possible, prioritize it by severity and exploitability, and coordinate disclosure after a fix or agreed mitigation is available. Do not send exploit code to a public issue tracker or social channel.
Current scope
parathoughtlabs.comand its Aura website endpoints;- authorized Aura iOS and Android private-beta builds;
- Aura-owned backend services explicitly identified in a beta; and
- accidental exposure of ParathoughtLabs credentials or private Aura data.
Third-party services are governed by their own disclosure programs. Report a weakness in Vercel, Resend, Apple, Google, AWS, or another provider directly to that provider unless the issue is caused by Aura’s configuration or application code.
Good-faith testing rules
- Test only accounts, devices, and data you own or are authorized to use.
- Stop immediately if you encounter another person’s data.
- Do not use denial of service, spam, social engineering, malware, or destructive tests.
- Do not degrade availability, alter records, persist access, or move laterally.
- Use the minimum proof necessary and securely delete retained test data after resolution.
No public bug bounty yet
Aura does not currently operate a paid bug-bounty program and cannot promise compensation. Rewards must never be assumed or demanded as a condition for withholding a vulnerability. A formal program may be published after the production security and incident-response teams are staffed.