Security
Assertion holds two kinds of customer data: the memory our products build from your work, and the business data you upload to Analytics. This page says where both live, who can reach them, what we do and do not keep, and how to tell us when something looks wrong. It is written to answer a security review without a call.
At a glance
- Hosting
- Google Cloud Platform and Firebase, managed services only, United States regions.
- In transit
- TLS 1.2 or higher, everywhere, including between our own services.
- At rest
- Encrypted by the cloud provider, with keys the provider manages.
- Staff access
- Single sign-on with multi-factor authentication, least privilege, reviewed regularly.
- Model training
- No customer data is used to train any model, ours or a provider’s.
- Tenancy
- Logical isolation by organisation, enforced at every read and write.
- Penetration testing
- Independent third party, at least annually.
- Compliance
- SOC 2 Type II examination under way. Report available under NDA.
- Security contact
- security@assertion-ai.com
Where the platform runs
The platform runs on Google Cloud Platform and Firebase, in United States regions. We use managed, serverless services rather than servers we patch ourselves. That is a deliberate trade: we give up some control over the machine in return for a smaller attack surface, configuration that cannot drift between one instance and the next, and security updates that arrive without us shipping a release.
The marketing site you are reading is static, hosted separately, and holds no customer data.
Encryption and access
Customer data is encrypted in transit with TLS 1.2 or higher, and encrypted at rest by our cloud providers. This applies between our own services as well as between you and us.
Access to production follows least privilege and need to know. Staff reach production systems through single sign-on with multi-factor authentication, access is granted by role rather than by person, and we review who holds what on a regular basis. Access to systems that process customer data is logged.
What memory stores
This is the part of Assertion most worth understanding, because it is the part people assume works differently than it does.
- We do not keep your transcripts. Memory stores distilled claims, a decision, a constraint, a finding, together with a short excerpt of the evidence behind it. The conversation it came from is not retained.
- We do not keep your source code. A claim may name a file or quote a few lines as evidence. Your repository stays yours and is never copied to us.
- Everything kept is visible to you. Every claim, its evidence and the full memory log are readable in Studio, and anything wrong can be corrected or removed there. Memory you cannot inspect is memory you cannot trust.
- Personal memory stays personal. A claim captured in your own space is visible only to you. It reaches teammates only in a shared space that you or your organisation created.
- Analytics data is different. A file you upload to Analytics is held in that project, in full, because the analysis needs it. It stays inside your organisation and is deleted with the project.
Training and model providers
We do not use customer data to train models, either our own or for other customers, and we do not sell it. Prompts and results are used to serve your request and for nothing else.
Our products call large language models from third-party providers. Those providers are contractually prohibited from using customer data to train or improve their models, and we use the enterprise terms that carry that commitment rather than consumer accounts. Where a model is called, only the content needed for that request is sent.
Separation and deletion
Customer data is logically isolated by organisation. Isolation is enforced at every read and write rather than by a filter applied at the edge, so a request carries its organisation with it and cannot reach another one by being pointed somewhere else.
You can remove what you no longer want us to hold. Individual claims can be corrected, superseded or deleted from Studio at any time. Deleting a project removes its data and its analyses. To close an account and have the data behind it deleted, write to support@assertion-ai.com, and we will confirm when it is done. Retention periods for personal data are set out in our data privacy notice.
Finding problems before you do
We run automated static analysis and dependency scanning on every change to our codebase, and an independent third party performs penetration testing at least annually. Findings are triaged by risk and fixed on that basis rather than in the order they arrive.
We log access to production and material operations on it, and retain those logs to support monitoring, investigation and audit.
If something goes wrong
We maintain an incident response plan that covers detection, containment, investigation and communication, and we exercise it. If we confirm a security incident affecting your data, we will tell you, in line with our agreement with you and applicable law, and we will say what we know rather than waiting until we know everything.
Who else touches the data
We use a small number of third parties to run the platform. Each is bound by terms that restrict their use of your data to providing their service to us.
- Google Cloud Platform and Firebase
Hosting, databases and storage. United States. - Anthropic, OpenAI and Google
Large language models, called to serve your requests. Contractually prohibited from training on your data. - Stripe
Payments. Card details go to Stripe directly and we never hold them.
If you need to be told before this list changes, say so in your agreement with us and we will write it in. Ask security@assertion-ai.com for the current list at any time.
Compliance
We are undergoing a SOC 2 Type II examination. A copy of the report, and our completed answers to the standard security questionnaires, are available to customers and prospects under NDA. Ask security@assertion-ai.com.
Where we process personal data on your behalf, our Data Processing Addendum applies. It is referenced by our Terms and available on request.
Reporting a problem
If you think you have found a vulnerability, write to security@assertion-ai.com. Please include enough detail for us to reproduce it: what you did, what happened, and what you expected instead. A proof of concept helps.
- We acknowledge within one working day and tell you who is looking at it.
- We will keep you posted while we investigate, and tell you when the fix ships.
- Please give us time to fix it before disclosing it publicly. We will not take legal action over research reported in good faith that stays within your own account and does not degrade the service for anyone else.
For anything that is not a security problem, Help has the routes for support, billing and account questions.