Security

Security defaults you can trust.

We treat security as a product feature, not a checkbox. Here is how we protect your data — explained without legalese.

Database-per-tenant

Every workspace gets its own PostgreSQL database. Cross-tenant data leaks are not a 'we promise' control — they are physically impossible.

Encryption everywhere

TLS 1.2+ in transit; AES-256 at rest. Backups are encrypted with separate keys.

Defence in depth

Helmet security headers, rate limiting, RBAC, magic-byte file verification, parameterised SQL via Prisma.

Immutable audit log

Every asset event — create, update, check-out, check-in, license assign, ticket open — is captured and exportable.

Scoped API keys

Tenant-scoped, hashed at rest, support read-only or read-write, with revocation and expiry.

Signed webhooks

HMAC-SHA256 signed deliveries with timestamp, three-attempt retry, full delivery audit log.

Frameworks & alignment

  • GDPR / DPDP-ready

    DPA available on every paid plan; data subject access and erasure workflows.

  • ISO 27001 controls mapping

    Asset inventory (A6.5), acceptable use (A6.6), return (A6.7), media disposal (A7.10).

  • SOC 2 alignment (in progress)

    Annual penetration tests, vulnerability scans, change-management process.

  • OWASP top 10

    Reviewed quarterly; recent VAPT report available under NDA on request.

Data Processing Addendum (DPA)

We sign a DPA with every paid customer. It covers GDPR Article 28 obligations, subprocessor list, breach notification, and sub-processing terms. Email security@assetmon.app for the latest version or to start an InfoSec review.