AssurAI is built for audit and compliance professionals who handle the most sensitive financial and operational data in their organisations. Here's exactly how we protect it.
DDoS protection, web application firewall, bot mitigation, global edge caching across 300+ cities
Serverless functions, SSL/TLS termination, atomic deployments, zero-downtime updates. hosted on SOC 2 Type II certified infrastructure.
Managed PostgreSQL with row-level security, point-in-time recovery, automated backups every 24h retained for 7 days. SOC 2 Type II, ISO 27001, HIPAA eligible.
AI processing via Anthropic's API. Data sent for inference is not used for model training. Anthropic is hosted on SOC 2 Type II certified infrastructure.
All data between your browser and our servers is encrypted with TLS 1.3. Older protocols (TLS 1.0, 1.1) are rejected.
All database data is encrypted at rest using AES-256. This includes workpapers, findings, projects, and all user data.
Automated daily backups are encrypted before storage. Point-in-time recovery available for the last 7 days.
All AssurAI pages and APIs are served over HTTPS. HTTP requests are automatically redirected. HSTS enforced.
API keys and secrets are stored as encrypted environment variables. They are never embedded in code or logs.
Evidence files and attachments are stored in Supabase Storage with per-object access controls and signed URLs.
Admin, Manager, Auditor, and Reviewer roles with granular permissions per module.
MFA available for all users. Enterprise customers can enforce MFA organisation-wide.
Connect your identity provider (Okta, Azure AD, Google Workspace) for centralised access control.
Every action β view, create, edit, approve, export β is logged with timestamp, user, and IP address.
AssurAI staff can only access your data with your explicit written consent β for example, to diagnose a support issue you've reported.
Any support access is logged, time-limited, and immediately revoked when the issue is resolved.
Your data is never used to train AI models β by AssurAI or by Anthropic. AI inference is stateless.
Default region for all customers. Data centre in Northern Virginia. Suitable for US customers and those without specific data residency requirements.
Default β ActiveFrankfurt, Germany. GDPR-compliant data residency for EU/EEA customers. Data never leaves the EU. Available for Professional and Enterprise plans.
Available on requestLondon. Post-Brexit UK data residency for customers with UK GDPR requirements. Planned for rollout Q3 2026.
Planned Q3 2026Singapore. For customers in APAC region with local data residency requirements. Planned for rollout Q4 2026.
Planned Q4 2026| Provider | Purpose | Data processed | Location | Certifications |
|---|---|---|---|---|
| Supabase | Database, Authentication, Storage | All customer data | AWS us-east-1 (US) / eu-central-1 (EU) | SOC 2 Type II Β· ISO 27001 Β· HIPAA eligible Β· GDPR |
| Anthropic | AI / LLM inference | Prompts submitted for AI analysis | United States | SOC 2 Type II Β· No training on customer data |
| Netlify | Application hosting, CDN, Functions | Request logs, function execution | Global edge (AWS + GCP) | SOC 2 Type II Β· GDPR |
| Cloudflare | CDN, DDoS protection, WAF | Request metadata (no content) | Global edge network | SOC 2 Type II Β· ISO 27001 Β· GDPR |
| Resend | Transactional email | Email address, notification content | United States | SOC 2 Type II Β· GDPR |
| Stripe | Payment processing | Billing information only | United States | PCI DSS Level 1 Β· SOC 2 Β· ISO 27001 |
Automated monitoring alerts on anomalous access patterns, failed authentication spikes, or unusual data export volumes. Sentry monitors application errors in real-time.
On confirmed incident, affected accounts are immediately suspended and access tokens revoked. The attack surface is isolated within minutes.
We determine what data was accessed, by whom, and for how long. We assess whether it constitutes a personal data breach under GDPR Article 4(12).
Affected customers are notified with a plain-language summary of what happened, what data was affected, what we've done, and what they should do.
Root cause analysis, patch deployment, and a post-incident report published to affected customers. Process improvements implemented.
Email security@getassurai.com with details of the vulnerability. We will acknowledge within 48 hours and keep you informed of our progress.
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, following responsible disclosure principles.
We aim to patch critical vulnerabilities within 24 hours, high severity within 7 days, and medium severity within 30 days of confirmed report.
Verified reporters are acknowledged in our security hall of fame (with permission). We do not currently offer a paid bug bounty programme.
AssurAI targets 99.9% monthly uptime for all platform services. Planned maintenance is scheduled outside business hours and communicated in advance.
Real-time system status is available at status.getassurai.com. Subscribe to receive instant notifications when incidents are detected or resolved.
Enterprise customers receive direct email notification of any incident affecting their data or availability. We commit to a first response within 1 hour of confirmed incident.
Database backups run every 24 hours and are retained for 7 days. Point-in-time recovery is available for the last 7 days. Restore time objective (RTO): 4 hours.
AssurAI uses Anthropic's Claude API for AI analysis. Anthropic's enterprise API policy explicitly states that customer data submitted via the API is never used to train AI models. Your audit documents, findings, and workpapers are not used to improve Anthropic's models.
Anthropic retains API inputs and outputs for up to 30 days solely for trust and safety monitoring purposes, after which they are permanently deleted. This is standard practice for all enterprise API customers. No human reviews your data unless a safety violation is suspected.
Enterprise customers with heightened data sensitivity requirements can request a Zero Data Retention (ZDR) agreement with Anthropic, under which no API data is stored beyond the duration of the request. Contact shakeel@getassurai.com to arrange this.
AssurAI's infrastructure and Anthropic's API are currently hosted on US-based servers (AWS us-east-1). Data submitted for AI processing passes through US infrastructure. EU and other non-US customers should be aware of this cross-border data transfer. AssurAI provides a GDPR-compliant Data Processing Agreement (DPA) on request. We are monitoring Anthropic's EU region availability and will offer EU-based processing as soon as it becomes available.
AssurAI stores only the data you explicitly save to the platform β workpapers, findings, controls, and engagement files. Documents uploaded for Evidence Intelligence analysis are processed in memory and not permanently stored unless you explicitly save the output.
β Based on Anthropic's published data policy as of June 2026. Anthropic's policies may be updated. Please refer to anthropic.com/privacy for current terms.
Private Cloud and On-Premises deployments available on Enterprise plans. Contact us to discuss your requirements β
Our Data Processing Agreement (DPA) is available for all customers and covers GDPR Article 28 requirements. Read DPA β
Enterprise customers can request a customised DPA to accommodate specific jurisdictional or contractual requirements. Contact security@getassurai.com
Covers what personal data we collect, how it is used, retention periods (data deleted within 30 days of account closure), and your rights. Read Privacy Policy β
Our Terms of Service define the contractual relationship, acceptable use, SLA commitments, and liability limits. Read Terms β
We are happy to complete vendor security questionnaires (VSQs), provide our sub-processor list, or sign mutual NDAs prior to evaluation. Contact: security@getassurai.com