
Security
Last updated: August 11, 2026
Security is foundational to how we build and operate the Assertion AI platform. This page summarizes our practices.
Infrastructure
The Platform runs on managed cloud infrastructure (Google Cloud Platform and Firebase), hosted in the United States. We use a serverless, managed architecture rather than self-managed servers, which reduces our attack surface and keeps configuration consistent.
Encryption
Customer data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest by our cloud providers.
Access control
Access to production systems follows least-privilege and need-to-know principles. We enforce single sign-on and multi-factor authentication for access to systems that process customer data, and we review access on a regular basis.
Vulnerability management
We use automated static analysis and dependency scanning on our codebase, engage an independent third party to perform penetration testing at least annually, and remediate findings on a risk-prioritized basis.
Monitoring and logging
We log access to and material operations on production systems and retain those logs to support monitoring, investigation, and audit.
Data handling
Customer data is logically isolated between customers and processed only to provide the Platform. Our AI service providers are contractually prohibited from using customer data to train or improve their models, and we do not use customer data to train models for other customers or for our general commercial use without consent.
Incident response
We maintain an incident response plan and will notify affected customers of confirmed security incidents in accordance with our agreements and applicable law.
Compliance
We are undergoing a SOC 2 Type II examination. A copy of our report and responses to standard security questionnaires are available to customers and prospects under NDA on request.
Contact
Report a security concern: security@assertion-ai.com