πŸ”’ Security & Trust Centre

Your audit data.
Protected by design.

AssurAI is built for audit and compliance professionals who handle the most sensitive financial and operational data in their organisations. Here's exactly how we protect it.

All systems operational
Last updated: May 2026
πŸ›οΈ
SOC 2 Type II
Via Supabase
Our database infrastructure is hosted on SOC 2 Type II certified infrastructure. AssurAI-level certification planned for 2027.
πŸ‡ͺπŸ‡Ί
GDPR
Compliant
DPA signed with all sub-processors. EU data residency available on request.
πŸ”
Encryption
AES-256 + TLS 1.3
All data encrypted at rest and in transit. Zero plaintext storage.
πŸ“‹
AssurAI SOC 2
Planned Q1 2027
We will obtain our own SOC 2 Type II certification as we scale.
Built on enterprise-grade infrastructure
AssurAI runs on AWS (via Supabase) and Netlify's global edge network β€” the same infrastructure used by thousands of enterprise SaaS platforms.
🌐

Cloudflare CDN + WAF

DDoS protection, web application firewall, bot mitigation, global edge caching across 300+ cities

LAYER 1
↓
⚑

Netlify Edge Network

Serverless functions, SSL/TLS termination, atomic deployments, zero-downtime updates. hosted on SOC 2 Type II certified infrastructure.

LAYER 2
↓
πŸ—„οΈ

Supabase PostgreSQL (AWS us-east-1)

Managed PostgreSQL with row-level security, point-in-time recovery, automated backups every 24h retained for 7 days. SOC 2 Type II, ISO 27001, HIPAA eligible.

LAYER 3
↓
πŸ€–

Anthropic Claude API

AI processing via Anthropic's API. Data sent for inference is not used for model training. Anthropic is hosted on SOC 2 Type II certified infrastructure.

LAYER 4
End-to-end encryption β€” always on
Your data is encrypted at every stage β€” in transit, at rest, and in backups. There is no configuration option to disable encryption.
βœ“

TLS 1.3 in transit

All data between your browser and our servers is encrypted with TLS 1.3. Older protocols (TLS 1.0, 1.1) are rejected.

βœ“

AES-256 at rest

All database data is encrypted at rest using AES-256. This includes workpapers, findings, projects, and all user data.

βœ“

Encrypted backups

Automated daily backups are encrypted before storage. Point-in-time recovery available for the last 7 days.

βœ“

HTTPS everywhere

All AssurAI pages and APIs are served over HTTPS. HTTP requests are automatically redirected. HSTS enforced.

βœ“

Secrets management

API keys and secrets are stored as encrypted environment variables. They are never embedded in code or logs.

βœ“

Secure file storage

Evidence files and attachments are stored in Supabase Storage with per-object access controls and signed URLs.

Every evidence file is cryptographically sealed
AssurAI generates a SHA-256 hash of every uploaded evidence file at the moment of ingestion. If the file is modified β€” even by a single byte β€” the hash will not match. This creates a tamper-evident audit trail that meets PCAOB and Big 4 inspection standards.
SHA-256
Cryptographic Hashing
Every evidence file is hashed with SHA-256 on upload. The hash is stored separately and re-verified on every access. Tampering is mathematically detectable.
SEAL
Tamper-Evident Trail
Workpaper packages include an Evidence Integrity Certificate listing each file, its hash, and the timestamp it was sealed. Inspectors can independently verify the chain of custody.
CERT
Evidence Integrity Certificate
Each redboxed evidence package exports a machine-readable integrity certificate. Suitable for external auditor handoff, regulatory submissions, and PCAOB inspection support files.
Your data is yours β€” completely isolated
AssurAI uses a multi-tenant architecture with strict row-level security. No customer can ever access another customer's data.
STARTER & PROFESSIONAL
Shared Database, Isolated Data
All customers share one database infrastructure, but your data is strictly isolated by organisation ID using PostgreSQL Row Level Security (RLS). Every query is automatically scoped to your organisation β€” it is architecturally impossible to query another organisation's data.
Standard SaaS model
ENTERPRISE
Dedicated Database Instance
Enterprise customers receive a dedicated PostgreSQL database instance. Your data is physically separated from all other customers at the infrastructure level. Available in US or EU region.
Available on request
ALL TIERS
Sandbox Environment
Every account includes a sandbox environment for testing. Sandbox and production data are completely separate β€” test data never touches your live audit records.
Included free
RLS
Row Level Security
PostgreSQL RLS policies enforce that every database query β€” without exception β€” is scoped to your organisation. This happens at the database engine level, not in application code.
ORG
Organisation Isolation
Every record in AssurAI carries an org_id. The database rejects any query that attempts to read or write data across organisation boundaries.
JWT
Token-bound Access
Every API request is authenticated by a short-lived JWT. Tokens expire after 1 hour. Refresh tokens are rotated on each use and can be revoked instantly.
Who can access what β€” and when
AssurAI operates on a strict need-to-know basis, both for your team members and for AssurAI staff.

Your team's access

βœ“

Role-based access control (RBAC)

Admin, Manager, Auditor, and Reviewer roles with granular permissions per module.

βœ“

Multi-factor authentication

MFA available for all users. Enterprise customers can enforce MFA organisation-wide.

βœ“

SSO / SAML 2.0

Connect your identity provider (Okta, Azure AD, Google Workspace) for centralised access control.

βœ“

Audit trail

Every action β€” view, create, edit, approve, export β€” is logged with timestamp, user, and IP address.

AssurAI staff access

βœ“

Support access by consent only

AssurAI staff can only access your data with your explicit written consent β€” for example, to diagnose a support issue you've reported.

βœ“

Logged and time-limited

Any support access is logged, time-limited, and immediately revoked when the issue is resolved.

βœ“

No AI training on your data

Your data is never used to train AI models β€” by AssurAI or by Anthropic. AI inference is stateless.

Your data stays where you need it
Choose where your data is stored to meet local regulatory requirements, including GDPR data residency obligations for European customers.
πŸ‡ΊπŸ‡Έ

United States β€” AWS us-east-1

Default region for all customers. Data centre in Northern Virginia. Suitable for US customers and those without specific data residency requirements.

Default β€” Active
πŸ‡©πŸ‡ͺ

European Union β€” AWS eu-central-1

Frankfurt, Germany. GDPR-compliant data residency for EU/EEA customers. Data never leaves the EU. Available for Professional and Enterprise plans.

Available on request
πŸ‡¬πŸ‡§

United Kingdom β€” AWS eu-west-2

London. Post-Brexit UK data residency for customers with UK GDPR requirements. Planned for rollout Q3 2026.

Planned Q3 2026
🌏

Asia Pacific β€” AWS ap-southeast-1

Singapore. For customers in APAC region with local data residency requirements. Planned for rollout Q4 2026.

Planned Q4 2026
Third parties that process your data
We maintain a complete list of sub-processors who may process your data. We will notify you of any changes 30 days in advance.
Provider Purpose Data processed Location Certifications
Supabase Database, Authentication, Storage All customer data AWS us-east-1 (US) / eu-central-1 (EU) SOC 2 Type II Β· ISO 27001 Β· HIPAA eligible Β· GDPR
Anthropic AI / LLM inference Prompts submitted for AI analysis United States SOC 2 Type II Β· No training on customer data
Netlify Application hosting, CDN, Functions Request logs, function execution Global edge (AWS + GCP) SOC 2 Type II Β· GDPR
Cloudflare CDN, DDoS protection, WAF Request metadata (no content) Global edge network SOC 2 Type II Β· ISO 27001 Β· GDPR
Resend Transactional email Email address, notification content United States SOC 2 Type II Β· GDPR
Stripe Payment processing Billing information only United States PCI DSS Level 1 Β· SOC 2 Β· ISO 27001
What happens if something goes wrong
We have a documented incident response procedure. In the event of a confirmed data breach, we will notify affected customers within 72 hours β€” meeting GDPR Article 33 requirements.
1

Detection

Automated monitoring alerts on anomalous access patterns, failed authentication spikes, or unusual data export volumes. Sentry monitors application errors in real-time.

Continuous monitoring
2

Containment

On confirmed incident, affected accounts are immediately suspended and access tokens revoked. The attack surface is isolated within minutes.

Within 1 hour of detection
3

Assessment

We determine what data was accessed, by whom, and for how long. We assess whether it constitutes a personal data breach under GDPR Article 4(12).

Within 24 hours
4

Customer notification

Affected customers are notified with a plain-language summary of what happened, what data was affected, what we've done, and what they should do.

Within 72 hours β€” meeting GDPR Article 33
5

Remediation & review

Root cause analysis, patch deployment, and a post-incident report published to affected customers. Process improvements implemented.

Within 30 days
Found a security issue? Tell us.
We take security reports seriously. If you discover a vulnerability in AssurAI, please report it responsibly and we will respond within 48 hours.
βœ‰

Report to us

Email security@getassurai.com with details of the vulnerability. We will acknowledge within 48 hours and keep you informed of our progress.

βœ“

Safe harbour

We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, following responsible disclosure principles.

⏱

Our commitment

We aim to patch critical vulnerabilities within 24 hours, high severity within 7 days, and medium severity within 30 days of confirmed report.

πŸ™

Recognition

Verified reporters are acknowledged in our security hall of fame (with permission). We do not currently offer a paid bug bounty programme.

Reliability you can audit against
We design for high availability and notify Enterprise customers of any incidents that affect their access to audit data.
βœ“

99.9% uptime target

AssurAI targets 99.9% monthly uptime for all platform services. Planned maintenance is scheduled outside business hours and communicated in advance.

βœ“

Status page

Real-time system status is available at status.getassurai.com. Subscribe to receive instant notifications when incidents are detected or resolved.

βœ“

Incident notifications

Enterprise customers receive direct email notification of any incident affecting their data or availability. We commit to a first response within 1 hour of confirmed incident.

βœ“

Automated backups

Database backups run every 24 hours and are retained for 7 days. Point-in-time recovery is available for the last 7 days. Restore time objective (RTO): 4 hours.

How AI processing works β€” and what Anthropic holds
AssurAI uses Claude, Anthropic's AI, for intelligent analysis. Here is exactly what that means for your data.
βœ“

Anthropic does not train on your data

AssurAI uses Anthropic's Claude API for AI analysis. Anthropic's enterprise API policy explicitly states that customer data submitted via the API is never used to train AI models. Your audit documents, findings, and workpapers are not used to improve Anthropic's models.

βœ“

API data retention: up to 30 days

Anthropic retains API inputs and outputs for up to 30 days solely for trust and safety monitoring purposes, after which they are permanently deleted. This is standard practice for all enterprise API customers. No human reviews your data unless a safety violation is suspected.

βœ“

Zero Data Retention available

Enterprise customers with heightened data sensitivity requirements can request a Zero Data Retention (ZDR) agreement with Anthropic, under which no API data is stored beyond the duration of the request. Contact shakeel@getassurai.com to arrange this.

βœ“

EU and non-US customers

AssurAI's infrastructure and Anthropic's API are currently hosted on US-based servers (AWS us-east-1). Data submitted for AI processing passes through US infrastructure. EU and other non-US customers should be aware of this cross-border data transfer. AssurAI provides a GDPR-compliant Data Processing Agreement (DPA) on request. We are monitoring Anthropic's EU region availability and will offer EU-based processing as soon as it becomes available.

βœ“

What AssurAI itself stores

AssurAI stores only the data you explicitly save to the platform β€” workpapers, findings, controls, and engagement files. Documents uploaded for Evidence Intelligence analysis are processed in memory and not permanently stored unless you explicitly save the output.

† Based on Anthropic's published data policy as of June 2026. Anthropic's policies may be updated. Please refer to anthropic.com/privacy for current terms.

Runs where your data lives
AssurAI supports three deployment models to meet your organisation's data residency, security, and compliance requirements.
STARTER & PROFESSIONAL
☁️ Standard Cloud
Managed multi-tenant SaaS. Hosted on Netlify + Supabase (AWS us-east-1). Enterprise-grade tenant isolation via PostgreSQL Row Level Security. Live in minutes. No infrastructure to manage.
Default β€” all plans
ENTERPRISE
🏒 Private Cloud (VPC)
Dedicated single-tenant deployment inside a private VPC. Custom data residency β€” US or EU. Physically separate database instance. No shared infrastructure with other customers. Ideal for regulated industries.
Enterprise β€” contact us
ENTERPRISE
πŸ”’ On-Premises
Deployed inside your own network. LLM API calls use zero-retention endpoints β€” no data leaves your perimeter. Full control over all data flows. Suitable for organisations with strict data sovereignty requirements.
Enterprise β€” contact us

Private Cloud and On-Premises deployments available on Enterprise plans. Contact us to discuss your requirements β†’

Legal frameworks for enterprise compliance
We provide the legal documentation your procurement, legal, and compliance teams need to approve AssurAI as a vendor.
βœ“

Standard DPA included

Our Data Processing Agreement (DPA) is available for all customers and covers GDPR Article 28 requirements. Read DPA β†’

βœ“

Custom DPA for Enterprise

Enterprise customers can request a customised DPA to accommodate specific jurisdictional or contractual requirements. Contact security@getassurai.com

βœ“

Privacy Policy

Covers what personal data we collect, how it is used, retention periods (data deleted within 30 days of account closure), and your rights. Read Privacy Policy β†’

βœ“

Terms of Service

Our Terms of Service define the contractual relationship, acceptable use, SLA commitments, and liability limits. Read Terms β†’

πŸ“§

Vendor security questionnaires & contact

We are happy to complete vendor security questionnaires (VSQs), provide our sub-processor list, or sign mutual NDAs prior to evaluation. Contact: security@getassurai.com

Security questions? Talk to us directly.

We're happy to complete vendor security questionnaires, provide our sub-processor list, or discuss your specific compliance requirements.