Security · updated August 7, 2026

Protect the record and report concerns safely.

Aurmora treats progress references, routine history and support records as sensitive.

App protections

  • Accountless, local-first architecture
  • Independent AES-GCM encryption for persisted media
  • Metadata stripping and authenticated record context
  • Keychain-held key material
  • Atomic media writes and complete deletion paths
  • Optional app lock and app-switcher privacy shield

Website protections

  • WordPress capability checks and nonces
  • Strict field allowlists and escaped output
  • Honeypot, minimum-fill-time and keyed rate controls
  • Owner-only submission access and privacy-tool integration
  • Configurable retention cleanup

Contact

Report a security concern to hello@getaurmora.com. Do not send passwords, progress photos, medical records or payment information.

Coordinated reporting

Do not include exploit code, personal data, photos or credentials in the initial form. Do not access, change, retain or disclose another person’s information, perform denial-of-service testing or publish details before coordinated review.

Report a security concern

Do not include exploit code, personal data, progress photos or credentials in this form. We will reply with a safer channel if sensitive evidence is needed.

Fields marked required must be completed.

Website requests are retained only as long as needed for response, legal obligations and abuse prevention. See the Privacy Policy.