Security & Data Safeguards
Effective Date: 29 July 2026
Tenant Isolation & Cryptographic Integrity
AzuraOS enforces strict per-user database security rules. Every read and write to Cloud Vault Firestore requires active authentication and matching UID authorization.
1. Encryption in Transit & At Rest
All API calls, sync operations, and authentication tokens are encrypted in transit using modern TLS 1.3 encryption protocols. Cloud Firestore database collections are encrypted at rest using Google Cloud AES-256 standard keys.
2. Zero-Knowledge Local State
In Local Vault mode, your financial numbers never touch an external server. Data is stored strictly inside your device's browser indexed storage and localStorage.
3. Authentication & OAuth Security
Authentication is powered by Google Identity Services and Firebase Auth. OAuth tokens acquired for Google Calendar integration are retained on the client and transmitted using Bearer authorization headers without storing your account passwords.