Security and privacy decision

Aura

A small team or solo developer can realistically build a breach-scanning and alert MVP, but reproducing Aura’s full product (3-bureau credit monitoring, insurance, fraud remediation, VPN/antivirus, and parental safe-gaming integrations) requires partnerships and operational scale that make self-build impractical for most users.

Visit website
Subscription$13/month ✓ verified
Initial build30 hours
Monthly upkeep8 hours + $20
Evidence2/3 runs agree

No open-source build does this yet

Nothing published replaces this one, so a replacement starts from an empty file. Here is what it would have to cover.

What a replacement has to do

  • Collect user identifiers (email/SSN/phone), scan breach / dark-web sources for those identifiers on a schedule, store results and produce alerts, and let users view/manage monitored items in a simple web UI.

What it still won’t have

  • 3-bureau credit monitoring (Experian/TransUnion/Equifax) and instant credit lock
  • Identity theft insurance and white-glove US-based fraud remediation
  • Integrated VPN, antivirus, and password manager bundles
  • Parental controls, safe gaming voice/text monitoring, and child SSN monitoring
  • Large-scale proprietary dark-web indexing and real-time financial transaction monitoring

What remains hard

  • Product polish and ongoing maintenance
Read the build prompt

First-year cost

Keep paying

Paying ischeaper in year one.

On cash alone, building overtakes the subscription at 2 seats.

Paid seatsseats

Money you would actually spend

Keep paying

Subscription price × seats × 12

Build it

AI build APIs + hosting

Time you would spend

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a minimal identity-breach monitoring web app using Node.js + Express, Postgres, Redis, and React. Core features: (1) secure user signup and storing of monitored identifiers (email, phone, SSN token) with encryption at rest; (2) scheduled breach scans using a public breach API (HaveIBeenPwned or similar) and an adapter to ingest dark-web results; (3) an alerting system that sends email (SendGrid) and optional SMS (Twilio) when new exposures are detected; (4) React dashboard to add/remove monitored items and view exposure timeline; (5) background worker with retry, rate-limit handling, and audit logs. Out of scope: credit bureau integrations, insurance, VPN/antivirus, parental voice/text monitoring, and white-glove remediation. Include input validation, error handling, unit and integration tests for the scanning and alert pipeline, and Docker Compose for local dev.
How we checked2 sources · 2/3 runs agreed · evidence score 56

How the score was reached

  • Partly verdict base52
  • 2 cited sources+1
  • Price verified on pricing page+3
  • Evidence score56

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.

How scoring works →

Cited sources · 2

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page! 2 of 3 runs agreed; the verdict is the majority✓ Citations limited to fetched pages! 1 moat recorded