1. Our approach
Auryn Connect is under development. Its architecture is being designed around practical risk reduction, secure defaults and clear business control. This page describes design principles, not certifications, guarantees or claims that every future control is already operational.
2. Least privilege and data minimization
Connected services should request only permissions needed for enabled functionality. We plan to limit collection and retention to relevant operational, contractual, security and legal needs, and to keep high-risk access separate from ordinary product use.
3. Credentials and secret management
Integration credentials, tokens and application secrets are intended to be handled server-side, kept outside public configuration and source code, protected through environment-specific secret storage, and made revocable. Customers should never send credentials by email or through public website links.
4. Transport and access controls
Production services are intended to use HTTPS for data in transit, authenticated access, role-appropriate authorization and separation between public marketing routes and future authenticated application routes. No transmission or storage system can be guaranteed absolutely secure.
5. Secure operations
Our development approach is intended to include dependency review, change control, environment separation, security-aware logging, recovery planning and appropriate auditability. Logs should minimize sensitive content while preserving information needed to investigate failures and abuse.
6. Revocable integrations
Authorized businesses should be able to review and revoke integration access where supported. Revocation may need to be completed both within Auryn Connect and in the connected provider’s settings. Security events may require us to suspend a connection while risk is assessed.
7. Shared responsibility
Business customers remain responsible for their users, device and account security, lawful messaging, permission choices, connected-platform configuration and promptly reporting suspicious activity. Third-party services retain responsibility for their own systems.
8. Responsible vulnerability disclosure
If you believe you have found a security issue, email securityconnect@auryn.co.in with a clear description and safe reproduction details. Do not access data that is not yours, disrupt services, use social engineering, or publicly disclose an unresolved issue. We will acknowledge and triage credible reports submitted through this channel.