AuroraMed v0.2.0 is a synthetic-data pilot. See exactly what's built →

Solutions

Controls, findings and limits, in one place

IT and security teams should ask hard questions. This page and the Trust Center answer them, including where we fall short.

Implemented in the pilot Pilot

  • Deny-by-default roles with tenant isolation tests.
  • TOTP MFA, recovery codes, lockout, generic login errors.
  • Field encryption for national IDs and MFA secrets.
  • Hash-chained audit log; CSP and security headers; sandboxed desktop app.
  • Signed configuration with locked safety floors.

Open findings Open

  • Demo signing key in the demo code base.
  • PBKDF2 instead of Argon2id; no breached-password check.
  • No key rotation or per-tenant keys.
  • Audit chain not write-once; no per-IP rate limit.
  • No independent review or penetration test.

Open the Trust Center

Talk to us about it and security

A short walkthrough on synthetic data. No patient information needed.

See the synthetic-data demo first.Request a demo