Security & data protection
Last updated · 19 July 2026
Augora is built for regulated wealth-management and financial-advice firms, who trust us with confidential client information. This page summarises the technical and organisational measures we use to protect that data. It is written for advisers, paraplanners, IT and compliance teams reviewing Augora as part of their due diligence.
Where Augora processes personal data on behalf of a customer firm, the firm is the controller and Augora is the processor. The full contractual detail is set out in our Data Processing Addendum, which is available on request (see Supporting your due diligence).
1. Hosting and data residency
Augora’s own infrastructure (application hosting, databases and file storage) runs on Amazon Web Services in the United Kingdom / European Economic Area (London region). Some approved sub-processors, including our AI model provider, may process data outside the UK/EEA. Where they do, we rely on an appropriate safeguard such as UK adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.
2. Encryption
Customer data is encrypted in transit using TLS and at rest using AES-256, including encrypted database storage and encrypted file storage. Secrets and credentials are held in a managed secrets store and are never stored in plaintext in our application code.
3. Access control and authentication
Access to systems and customer data is restricted to authorised personnel on a need-to-know basis. Users authenticate through our identity provider, and administrative and diagnostic tools use appropriate access controls, including multi-factor authentication where available. Augora does not store user passwords; credential storage is handled by our authentication provider.
4. Tenant isolation
Each customer firm operates in its own logically separated tenant or workspace. Users are scoped to their organisation, and one firm’s data is never combined with another’s. Firm administrators control authorised users and organisation-level settings within their workspace.
5. Isolated document processing
When Augora reads and processes case documents, the work runs in a temporary, isolated sandbox environment. These sandboxes do not have general internet access, hold only the data needed for that piece of work, and are destroyed after a period of inactivity or when the session ends. Augora reads from your source files; it does not alter your original records.
6. AI model use and training
Augora uses third-party AI model providers to perform inference. In other words, they analyse the materials you provide and generate drafts. We do not use customer personal data to train AI models, and we do not permit our AI model providers to train their models on customer personal data, unless a customer expressly agrees otherwise in writing.
7. Human review
Augora produces working drafts and workflow assistance for professional review. Every output is intended to be checked and approved by a competent human before use. Augora does not provide advice to end clients; your people do.
8. Retention and deletion
Customer file and conversation retention is configurable through organisation-level settings where available. Following termination of a customer’s agreement, customer personal data is deleted within 30 days, unless retention is required or permitted for legal, security, audit, dispute-resolution, accounting, compliance or backup purposes, or where the customer has selected a longer lawful retention setting. Saved outputs remain available for the customer to download or export; Augora is not the customer’s system of record.
9. Logging and monitoring
We maintain security, access, audit, diagnostic and service-integrity logs to operate the platform, investigate issues and meet our legal and contractual obligations. Diagnostic and observability tooling is used to keep the platform reliable and secure, with access restricted to authorised personnel.
10. Sub-processors
We use a small number of carefully selected sub-processors to provide, host, secure and support the platform, including cloud hosting and storage, an AI model provider, authentication, transactional email, error monitoring and product analytics. Each sub-processor is bound by written data-protection obligations materially equivalent to our own. A named sub-processor list is available on request as part of our Data Processing Addendum.
11. Personal data breaches
We maintain procedures to investigate, contain and mitigate security incidents. Where a personal data breach affects customer personal data, we will notify the affected customer without undue delay after becoming aware of it, and provide the information reasonably available to help the customer meet its own obligations.
12. Supporting your due diligence
We’re happy to support your own Data Protection Impact Assessment (DPIA) or supplier due diligence. Our Data Processing Addendum (DPA) and full sub-processor list form part of our customer contract and are available on request. The DPA includes a description of the processing, the technical and organisational measures summarised above, and the sub-processor list, so it can be used directly as an input to your DPIA. We can also complete a supplier security questionnaire.
To request these documents, or to ask a security question, email support@augora.co.
13. Contact
Augora Limited
Email: support@augora.co
Registered office: Ground Floor, Talbot House, Albion Street, Chester, United Kingdom, CH1 1RQ
Company number: 17256070
See also our Privacy & Cookie Policy.