Security
Security approach
Aurora One's security design is based on a few simple principles: everything possible runs under normal user authority, administrator permission is required only for narrow and fixed tasks, every downloaded package is verified, and limits are clearly written. We do not promise absolute security or perfection; We write down what is verified and what is not.
Interface running with normal authorization
The application runs with normal user privileges in daily use. Tasks that require administrative privileges (DNS rule for VPN, a single registry value, removing the old startup task, installing the update in the protected folder, and opening the on-screen keyboard) are done through a narrow-authorization helper in the protected installation. The helper's action list is fixed; There is no generic command execution or file writing interface, and the calling process is authenticated. If approval is rejected, no action is taken and the application remains open.
Beta: automatic tests of the helper were run with the dummy manager, without opening the real Windows confirmation window. End-to-end acceptance of the actual approval flow has not yet been recorded; That's why it appears in the catalog with the Beta badge.
Installation and update
- The installation is made in the protected folder under Program Files and Windows administrator approval is requested once for this step. The shortcuts are connected to a launcher that verifies the installation registry and the SHA-256 value of the application file.
- The update package is downloaded only via HTTPS and only from the broadcast address. The ECDSA P-256 signature is verified with its size, SHA-256 value, and the publisher key embedded in the application. Packages that are unsigned, have invalid signatures or belong to another channel will not be installed.
- Backup of records is taken before updating. The files of the previous two versions are retained.
- Known limit: package signature is not Windows code signature (Authenticode). The publisher may appear as "Unknown" in the admin confirmation window. There is no one-click return to previous version button within the application yet.
Embedded web views
- WhatsApp, Discord, YouTube, Twitch, Kick and browser sections are in separate profiles; subscription streaming services operate on a common profile. Password saving and autofill are off; There is no hyperlink between the page and the application.
- Each view navigates only to its own service's domains. Camera, microphone, location, notification, and dashboard read requests are denied in browser and broadcast views. You will be asked for microphone and camera on WhatsApp.
- Executable or script-capable file types are not downloaded. The downloaded file is marked as coming from the internet and will not open automatically. External links and files are opened with normal user rights, even if the application is running as an administrator.
- Encrypted DNS is on by default in embedded browser views. This setting does not change the DNS of Windows or other programs and does not hide the IP address.
VPN and network
- One-click VPN connects to public VPN Gate volunteer servers with Windows' built-in client; Aurora One does not carry its own VPN server or software. The default mode is split tunneling: only Discord address ranges are tunneled.
- Traffic passes through servers operated by volunteers; Sensitive tasks such as banking are not recommended when VPN is on. We do not guarantee the level of confidentiality of the tunnel.
- "Repair my network connection" only removes the VPN profile Aurora One added and its tagged DNS rule. It does not touch your network settings.
Records and logs
- Only the domain name is written to the connection event log. The full address, message content and login information are not written. Strings such as passwords, keys, and cookies are masked in the VPN diagnostic log.
- Tracking parameters are discarded when saving a bookmark, tab group, and page note. The value of secret parameters such as tokens is not written to disk.
- The diagnostic package is written only to the folder you select or copied to the clipboard; Paths with usernames are masked, notes and account information are not packaged.
Known limits
- Some third-party screen overlays (e.g. RTSS) may crash the embedded browser process; Aurora One cannot prevent this, it only shows the cause and the solution.
- The end-user version has not yet been accepted end-to-end on the real machine. The real machine proof to date is from the developer version.
- If you would like to report a vulnerability: the communication channel will be added to this page before publication.
Privacy page describes the data flow in tabular form; Security and privacy category lists related features.