Effective for this catalog: October 1, 2026 · Version 2026-10-01
ACCOUNTS
The current catalog does not collect or store passwords. The prepared secure-store connection uses Amazon Cognito sign-in, password recovery, email confirmation and authenticator-based multi-factor authentication after deployment. Research qualification is reviewed separately from email confirmation.
PAYMENTS
When activated, a payment provider will handle card and wallet credentials through the secure store. An order becomes paid only after the provider’s server confirmation; a browser redirect alone is not proof of payment. Visa, Mastercard, Google Pay and Alipay availability requires provider and merchant approval. Bank wire for US and Canadian customers is awaiting bank setup and verified payment reconciliation; selecting a preference does not authorize a transfer.
PROTECT YOUR ACCESS
Use a unique password for the secure account service. Check the account-service domain before entering credentials. AURA enquiry drafts should never contain payment card numbers, account passwords, patient details or identity documents.
VERIFICATION LIMITS
A 21+ checkbox is a self-declaration, not independent identity verification. A reviewed laboratory report characterizes the submitted sample; it is not a general safety certificate. No third-party identity-verification provider has yet been appointed.
OPERATIONAL CONTROLS BEFORE LAUNCH
The secure store must be configured for HTTPS, least-privilege staff access, backups, software updates, login protection and provider webhook verification. These launch requirements are not claims that unconnected services are already active.
BUSINESS & SUPPORT
The operating legal entity must be published before registration opens.
Privacy contact: Awaiting publication
Retention: Awaiting the approved retention schedule
Sale & returns: Final sale and return terms must be published before payments open.

