Security
Small surface. Clear services. No mystery backend.
Mac permissions
Microphone powers Ask and Dictate. Screen context is for visual questions. Accessibility is for explicit actions and paste output.
Static website
Aurras Web is a static export served by Caddy. No website backend, public database, or app server is required for v1.
- No backend is required for the launch website.
- The waitlist form is delegated to Tally and disclosed on the privacy page.
- PostHog is optional and configured for minimal website events.
- Security headers are enforced at Caddy for the static site.
Services
Tally handles the waitlist. PostHog is optional and limited to website events marked with surface: website.
Reports
Send security reports to [email protected]. Include affected URLs and reproduction steps.
