AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

Security controls · C0123

How are session tokens protected?

In the pilot (v0.2.0, synthetic data)

Short answer

Sessions use random 256-bit tokens stored as hashes on the server, expiring after a fixed period and revocable. Tokens sit in browser session storage, which the review lists as an accepted low risk.

This exists in the synthetic-data pilot only.

Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.

Related answers

See it in context: Sign-in, MFA and sessions · Search the help center · Ask a question

See the synthetic-data demo first.Request a demo