Aligned to control frameworks and standards
What Platform Security does
Zero-Trust, not perimeter trust.
An operational record is only worth what its integrity is worth. If anyone could alter a reading after the fact, the audit trail proves nothing. Assetas is built on Zero-Trust principles: nothing is trusted by default — not a network location, not a session, not an admin account.
The platform inherits Microsoft Azure's defense-in-depth cloud foundation — ISO 27001-certified facilities, segmented virtual networks with deny-by-default outbound policy, hardware-backed key storage — and layers Assetas-specific controls on top under a shared-responsibility model.

Six layers, continuously verified.
How it works
Identity, encryption, detection, development, resilience, and assurance —
each with its own controls and its own evidence.

01 — IDENTITY & ACCESS
Least privilege, enforced
Entra ID single sign-on with conditional access and MFA on privileged roles. Administrators get just-in-time elevation rather than standing access, and client-managed roles reach down to record-level and field-level permissions.

02 — ENCRYPTION
Encrypted everywhere, keys in hardware
TLS 1.2+ with forward secrecy in transit and HSTS forced on every endpoint. AES-256 at rest through Azure Transparent Data Encryption. Keys live in hardware-backed vaults with rotation automation — customer-managed keys available on request.

03 — DETECTION & RESPONSE
24×7 monitoring, defined response times
Continuous threat detection with automated containment, backed by a 24×7 SOC. Incident playbooks follow NIST 800-61, with severity levels that carry defined client-notification SLAs — a critical incident is a sub-hour notification, not a call whenever someone gets to it.

04 — DEV-SEC-OPS
Security in the pipeline, not after it
OWASP Top 10-aligned coding standards with automated SAST, DAST, and dependency checks running in CI/CD. Production changes are gated by peer review, automated testing, and a change-approval board — with continuous vulnerability scanning across OS, container, and code.

05 — RESILIENCE
Deep backups, regional redundancy
Active-active replication across paired Azure regions with automatic failover. Point-in-time recovery, rolling weekly and monthly offsite backups, and a recovery point objective measured in minutes — because an asset record you can't recover isn't a record.

06 — AUDIT & ASSURANCE
Immutable logs, exportable evidence
Every create, edit, sync, and sign-off is logged with the user, timestamp, and prior value — retained by default and configurable to multi-year windows. Logs export to your own SIEM, so the evidence supporting a NIST, ISO, or SOC 2 assessment lives in your environment too, not only in ours.
At a glance
The numbers behind the posture.
24x7
SOC monitoring & automated containment
≤15 min
recovery point objective
≤ 4 hrs
recovery time objective
1 yr
audit log retention, configurable
Shared responsibility, stated plainly
Assetas secures the application and the underlying cloud stack. Clients remain responsible for end-user devices and local network security, assigning and periodically reviewing user roles, and configuring data-retention settings to internal policy. We'd rather say that up front than let it surface during an audit.
Data governance
Your data, your jurisdiction, your control.
Privacy frameworks
DPA support for GDPR, CCPA, and PIPEDA, with HIPAA-aligned handling where applicable.
Classification & discovery
Automated discovery of sensitive data with policy enforcement across the environment.
You remain the controller
Clients own their data. Assetas acts as processor under a data-processing addendum.
Local & regional residency
Production data is stored in local and regional Azure centers, with defined continuity rollover.
