1. Purpose

The purpose of this Data Security Policy is to establish the principles, controls, responsibilities, and procedures used by Auracles to protect the confidentiality, integrity, availability, and lawful processing of information stored, transmitted, and managed through the Auracles platform.

This policy applies to all Contributors, Operators, employees, contractors, service providers, partners, and authorized users of the Auracles platform.

Auracles recognizes that trust is fundamental to the exchange of operational knowledge and intellectual property and is committed to maintaining appropriate security standards across its systems and operations.


2. Scope

This policy applies to all information processed through Auracles, including:

User Information

Account Information, Identity Verification Information, Contact Information, Professional Credentials.

Marketplace Information

Framework Metadata, Framework Content, Licensing Records, Ownership Records, Version Histories.

Financial Information

Transaction Records, Billing Information, Payout Information, Subscription Information.

Trust and Reputation Information

Reviews, Ratings, Attestations, Verification Status, Reputation Scores.

Operational Information

Activity Logs, Security Logs, Platform Analytics, Support Communications.


3. Security Principles

Auracles operates according to the following security principles:

Confidentiality

Information shall only be accessible to authorized individuals.

Integrity

Information shall remain accurate, complete, and protected from unauthorized modification.

Availability

Systems and information shall remain accessible to authorized users when required.

Least Privilege

Users and personnel receive only the minimum level of access required to perform authorized activities.

Accountability: Actions performed within the platform shall be traceable through logging and audit controls.

Security by Design: Security considerations shall be integrated into product design, development, deployment, and operational processes.


4. Data Classification

Auracles classifies information according to sensitivity levels:

  • Public Data: Information intentionally made publicly available.Examples: Public Profiles, Framework Listings, Marketplace Reviews, Public Reputation Scores.
  • Internal Data: Information intended for platform operations.Examples: Internal Analytics, Operational Metrics, Support Records.
  • Confidential Data: Information requiring restricted access.Examples: Purchased Framework Content, Private Communications, Transaction Information, Business Information.
  • Restricted Data: Highly sensitive information requiring enhanced protection.Examples: Identity Verification Records, Government Identification, Financial Account Information, Authentication Credentials, Security Logs.

5. Access Control

Auracles implements role-based access controls. Access to information is granted based on:

  • User Role
  • Business Need
  • Security Requirements
  • Regulatory Obligations

Contributor Access Rights: Contributors may access their own account information, frameworks, licensing records, financial records, and reputation info. They may not access other users' private data or internal platform systems.

Operator Access Rights: Operators may access their own account, purchased frameworks, transaction logs, licensing records, and reputation. They may not access contributor details beyond what is disclosed via transactions.

Administrative Access: Administrative access is restricted to authorized personnel and granted only when necessary for security operations, compliance, support, or platform maintenance. Administrative actions are logged and audited.


6. Authentication and Account Security

Auracles requires secure authentication measures. Users are responsible for:

  • Maintaining password confidentiality.
  • Protecting authentication devices.
  • Reporting suspected compromises.
  • Updating credentials when necessary.

Auracles may require Multi-Factor Authentication (MFA), password rotation, risk-based authentication, and identity verification.


7. Encryption Standards

Auracles employs encryption to protect information:

  • Data in Transit: Information transmitted between users and the platform shall be encrypted using secure transport protocols (TLS, HTTPS).
  • Data at Rest: Sensitive information stored by Auracles shall be encrypted where appropriate (Identity Verification Records, Financial Information, Credentials, Security Logs).

8. Intellectual Property Protection

Auracles recognizes the importance of protecting framework intellectual property. Security controls include access restrictions, license enforcement, watermarking, download controls, activity monitoring, ownership tracking, and provenance records. Unauthorized copying, redistribution, or misuse of frameworks is prohibited.


9. Monitoring and Logging

Auracles maintains logs for security and operational purposes (login events, access events, transaction activity, licensing activity, administrative actions, and security events). Logs are retained for security, legal, and compliance purposes.


10. Vulnerability Management

Auracles regularly evaluates systems for vulnerabilities through security reviews, penetration testing, vulnerability scanning, risk assessments, and infrastructure audits. Identified vulnerabilities are prioritized and remediated according to risk.


11. Incident Response

Auracles maintains procedures for responding to security incidents (unauthorized access, data exposure, credential theft, malware, service disruption, and intellectual property misuse).

1. Detect
2. Contain
3. Investigate
4. Remediate
5. Recover
6. Review

12. Breach Notification

Where required by applicable law, Auracles will notify affected users regarding security incidents involving personal information. Notifications may cover the nature of the incident, information affected, actions taken, and recommended user actions.


13. Third-Party Service Providers

Auracles may engage trusted third-party providers for cloud infrastructure, identity verification, payment processing, monitoring, analytics, and customer support. Third-party providers must meet appropriate security standards.


14. Data Retention and Disposal

Information is retained only as long as necessary for platform operations, licensing records, ownership tracking, legal obligations, and security purposes. When no longer required, data is deleted, archived, or anonymized. Framework provenance records may be retained indefinitely to preserve ownership and licensing history.


15. User Security Responsibilities

Contributors and Operators share responsibility for maintaining platform security. Users agree to:

  • Protect Credentials: Do not share passwords or authentication devices.
  • Secure Devices: Maintain secure devices used to access Auracles.
  • Report Security Concerns: Promptly report suspicious activity.
  • Respect Access Rights: Do not attempt to access unauthorized information.
  • Protect Purchased Content: Store frameworks securely and comply with licensing restrictions.

16. Prohibited Security Activities

Users may not attempt unauthorized access, circumvent security controls, reverse engineer platform systems, distribute malware, interfere with operations, exploit vulnerabilities, access another user's account, or use unauthorized automated tools. Violations may result in account suspension, termination, legal action, or referral to law enforcement.


17. Business Continuity and Disaster Recovery

Auracles maintains measures intended to support platform resilience and operational continuity, including data backups, redundant infrastructure, recovery procedures, and operational monitoring.


18. Security Governance

Security oversight is managed by Auracles management and authorized personnel. Oversight activities include policy enforcement, risk management, security reviews, compliance monitoring, and incident oversight.


19. Compliance

Auracles seeks to align its security practices with recognized industry principles and applicable legal requirements, including data protection regulations, privacy requirements, contractual obligations, and enterprise security standards.


20. Changes to This Policy

Auracles may update this Data Security Policy periodically. Material updates will be communicated through platform notifications, email communications, or website announcements. Continued use of the platform constitutes acceptance of revised policies.


21. Contact Information

Auracles Security Team

Email: admin@auracles.space

Website: https://www.auracles.space

By creating an account, accessing, or using Auracles, Contributors and Operators acknowledge that they have read, understood, and agreed to comply with this Data Security Policy and the security obligations described herein.

Be known for what you've built

Join the waitlist and help build the Framework Economy.