top of page
hero-security-posture.png

Operational data that proves compliance has to be data no one can quietly alter. Assetas runs on a Zero-Trust architecture over Microsoft Azure — encrypted end to end, monitored around the clock, replicated across regions.

Platform / Platform Security

Where your record meets its defenses.

Aligned to control frameworks and standards
What Platform Security does

Zero-Trust, not perimeter trust.

An operational record is only worth what its integrity is worth. If anyone could alter a reading after the fact, the audit trail proves nothing. Assetas is built on Zero-Trust principles: nothing is trusted by default — not a network location, not a session, not an admin account.

​

The platform inherits Microsoft Azure's defense-in-depth cloud foundation — ISO 27001-certified facilities, segmented virtual networks with deny-by-default outbound policy, hardware-backed key storage — and layers Assetas-specific controls on top under a shared-responsibility model.

Six layers, continuously verified.

How it works

Identity, encryption, detection, development, resilience, and assurance —

each with its own controls and its own evidence.

capability-01-identity-access.png

01 — IDENTITY & ACCESS

Least privilege, enforced

Entra ID single sign-on with conditional access and MFA on privileged roles. Administrators get just-in-time elevation rather than standing access, and client-managed roles reach down to record-level and field-level permissions.

capability-02-encryption-keys.png

02 — ENCRYPTION

Encrypted everywhere, keys in hardware

TLS 1.2+ with forward secrecy in transit and HSTS forced on every endpoint. AES-256 at rest through Azure Transparent Data Encryption. Keys live in hardware-backed vaults with rotation automation — customer-managed keys available on request.

capability-03-incident-response.png

03 — DETECTION & RESPONSE

24×7 monitoring, defined response times

Continuous threat detection with automated containment, backed by a 24×7 SOC. Incident playbooks follow NIST 800-61, with severity levels that carry defined client-notification SLAs — a critical incident is a sub-hour notification, not a call whenever someone gets to it.

capability-04-secure-sdlc.png

04 — DEV-SEC-OPS

Security in the pipeline, not after it

OWASP Top 10-aligned coding standards with automated SAST, DAST, and dependency checks running in CI/CD. Production changes are gated by peer review, automated testing, and a change-approval board — with continuous vulnerability scanning across OS, container, and code.

capability-05-continuity-recovery.png

05 — RESILIENCE

Deep backups, regional redundancy

Active-active replication across paired Azure regions with automatic failover. Point-in-time recovery, rolling weekly and monthly offsite backups, and a recovery point objective measured in minutes — because an asset record you can't recover isn't a record.

capability-06-audit-trail.png

06 — AUDIT & ASSURANCE

Immutable logs, exportable evidence

Every create, edit, sync, and sign-off is logged with the user, timestamp, and prior value — retained by default and configurable to multi-year windows. Logs export to your own SIEM, so the evidence supporting a NIST, ISO, or SOC 2 assessment lives in your environment too, not only in ours.

At a glance

The numbers behind the posture.

24x7

SOC monitoring & automated containment

≤15 min

recovery point objective

≤ 4 hrs

recovery time objective

1 yr

audit log retention, configurable

Shared responsibility, stated plainly
 

Assetas secures the application and the underlying cloud stack. Clients remain responsible for end-user devices and local network security, assigning and periodically reviewing user roles, and configuring data-retention settings to internal policy. We'd rather say that up front than let it surface during an audit.

Data governance

Your data, your jurisdiction, your control.

Privacy frameworks

​

DPA support for GDPR, CCPA, and PIPEDA, with HIPAA-aligned handling where applicable.

Classification & discovery

​

Automated discovery of sensitive data with policy enforcement across the environment.

You remain the controller

​

Clients own their data. Assetas acts as processor under a data-processing addendum.

Local & regional residency

​

Production data is stored in local and regional Azure centers, with defined continuity rollover.

Bring your security team to the demo.

bottom of page