Skip to content
Back to Aura

ParathoughtLabs security

Report a security issue privately.

We welcome good-faith reports that help protect Aura visitors, users, and infrastructure. Please avoid public disclosure until we have had a reasonable opportunity to investigate and remediate the issue.

Effective July 26, 2026

How to report

Email support@parathoughtlabs.com with “Aura security report” in the subject. Include the affected URL or component, impact, reproducible steps, and any supporting request or response details. Remove passwords, access tokens, payment information, and personal data that are not essential to the report.

We will acknowledge a credible report as soon as reasonably possible, prioritize it by severity and exploitability, and coordinate disclosure after a fix or agreed mitigation is available. Do not send exploit code to a public issue tracker or social channel.

Current scope

  • parathoughtlabs.com and its Aura website endpoints;
  • authorized Aura iOS and Android private-beta builds;
  • Aura-owned backend services explicitly identified in a beta; and
  • accidental exposure of ParathoughtLabs credentials or private Aura data.

Third-party services are governed by their own disclosure programs. Report a weakness in Vercel, Resend, Apple, Google, AWS, or another provider directly to that provider unless the issue is caused by Aura’s configuration or application code.

Good-faith testing rules

  • Test only accounts, devices, and data you own or are authorized to use.
  • Stop immediately if you encounter another person’s data.
  • Do not use denial of service, spam, social engineering, malware, or destructive tests.
  • Do not degrade availability, alter records, persist access, or move laterally.
  • Use the minimum proof necessary and securely delete retained test data after resolution.
ParathoughtLabs will not pursue legal action for accidental, good-faith research that follows this policy, avoids privacy and availability harm, and is reported promptly. This statement does not authorize activity that violates law or third-party rights.

No public bug bounty yet

Aura does not currently operate a paid bug-bounty program and cannot promise compensation. Rewards must never be assumed or demanded as a condition for withholding a vulnerability. A formal program may be published after the production security and incident-response teams are staffed.

© 2026 ParathoughtLabs. Aura is currently a private prototype. security.txt Privacy notice Terms of use Contact security