Security Report
AiRA Security Report: SSL, Headers & Data Protection
Latest update: 8 June 2026
AiRA values user security and privacy — see the full Privacy Policy. The production system uses baseline safeguards to help reduce security risk, including HTTPS, security headers, rate limiting, consent flow, and repository / dependency security checks. AiRA continuously reviews and monitors its security safeguards.
Latest Security Verification Results
SecurityHeaders.com returned Grade A
SSL Labs returned Grade A
Passed production web security baseline
Dependency scan found 0 Critical and 0 High findings
The production website responds normally with HTTP/2 200
Static code scan completed with 0 findings
No confirmed committed secrets were found
Content-Security-Policy is configured
Strict-Transport-Security is configured
X-Frame-Options: DENY is configured
X-Content-Type-Options: nosniff is configured
Referrer-Policy is configured
Permissions-Policy is configured
X-Powered-By header is not exposed
Active Security Safeguards
- AiRA uses HTTPS for connections between users and the website
- HSTS is enabled to reduce risks from insecure connections
- Required security headers are configured for the production system
- X-Powered-By is hidden to reduce system information exposure
- OAuth redirects are checked to reduce open redirect risk
- Rate limiting is used on important endpoints to reduce abnormal usage risk
- Consent flow is used before app access so users can review relevant terms and policies
- AiRA does not sell users' personal data
What We Help Protect
- Birth date, birth time, and birth location used for calculations
- Nickname or basic profile information
- Session/account metadata
- Consent status
- Payment flow metadata handled by external payment providers
AiRA does not directly store payment card details. Payment details are handled by external payment providers.
Security Contact
If you discover a security issue, please contact askmyaira@gmail.com with enough detail to reproduce the issue. Please avoid accessing, modifying, or extracting data that does not belong to you.