Security & Trust Center
Enterprise-Grade Security for Your Critical Asset Data
At AssetLab, security is fundamental. We've built our platform with enterprise-grade security, privacy-first design, and transparent practices to protect your asset information.
Security Controls at a Glance
Quick-reference summary for IT and procurement reviews. Full details in the sections below.
| Control | Implementation | Status |
|---|---|---|
| Encryption in Transit | TLS 1.3 | Active |
| Encryption at Rest | AES-256 via Supabase | Active |
| Data Residency | Canada - AWS ca-central-1 (Montreal) | Active |
| Authentication | Clerk - Passkeys & email OTP | Active |
| Multi-Tenant Isolation | PostgreSQL Row-Level Security | Active |
| Role-Based Access Control | Administrator, Manager, Staff, Requester | Active |
| SSO | Available for enterprise customers | Active |
| Audit Logging | Full activity tracking | Active |
| Penetration Testing | Periodic third-party; report on request (NDA) | Active |
| Uptime SLA | 99.5% guaranteed | Active |
| Automated Backups | Daily automated backups (every 24 hours) | Active |
| Disaster Recovery | Documented procedures | Active |
| No AI Processing | Customer data never sent to AI providers | Active |
| PIPEDA | Privacy by Design principles | Aligned |
Last reviewed: April 2026
Security & Data Protection
Multi-layered security architecture built for enterprise asset management. Your data is protected at every level.
Infrastructure Security
- TLS 1.3 Encryption - All data in transit protected with industry-leading encryption
- AES-256 at Rest - Database encryption via Supabase enterprise infrastructure
Application Security
- Row-Level Security - PostgreSQL RLS ensures complete data isolation
- Multi-Tenant Isolation - Organization-based data segregation
- Audit Logging - Comprehensive activity tracking and access logs
Access Management
- Role-Based Access Control - Administrator, Manager, Staff, and Requester roles
- SSO Support - Single Sign-On available for enterprise customers
Penetration Testing
We conduct periodic third-party penetration tests to validate our security controls and identify vulnerabilities before they can be exploited. Customers can request access to our latest pen test results under a mutual NDA.
- Periodic Testing - Independent security assessments conducted regularly
- Third-Party Auditors - Tests performed by qualified external security firms
- NDA-Protected Reports - Full findings available to customers under NDA
Compliance & Standards
Meeting Canadian standards for data protection and privacy. Built with compliance in mind from day one.
PIPEDA Aligned
Built with Canadian privacy principles in mind.
- Privacy by Design - Security and privacy considered in every feature
- Transparent Handling - Clear documentation of data processing activities
- User Consent - Consent collected before gathering personal information
Data Residency
Core application data is stored on Canadian servers. Authentication is handled by Clerk, which processes user identity data on US-based infrastructure.
- Clerk Authentication - User identity data processed in the US
- Canadian Privacy Laws - Subject to PIPEDA and provincial privacy legislation
Data Processing Agreement
A Data Processing Agreement is available for customers who require formal documentation of how we process personal data on their behalf. Request a copy to include in your internal procurement or compliance review.
Request DPA →Privacy & Data Protection
Your data, your rights, our commitment. We believe in transparent data practices and user control.
No AI Processing of Customer Data
Your customer data is never sent to third-party AI providers such as OpenAI, Anthropic, or Google AI. No customer data is analyzed by external machine learning models.
- No External AI Processing - Customer data stays within our secure infrastructure
- No Training Data - We never use your data to train AI models
Privacy Principles
- No Data Selling - We never sell, trade, or rent your data to third parties
- Minimal Collection - We only collect data necessary to provide our services
- Transparent Processing - Clear documentation of how we use your information
- User Control - You maintain full control over your data at all times
Your Data Rights (PIPEDA)
- Right to Access - Request a copy of all your personal information
- Right to Correction - Request corrections to inaccurate data
- Right to Deletion - Request deletion of your account and associated data
- Data Portability - Export your data in common formats (CSV, JSON)
Infrastructure & Reliability
Enterprise-grade infrastructure you can count on. Built for performance, designed for reliability.
Cloud Infrastructure
- Supabase Enterprise - PostgreSQL database with enterprise-grade reliability
- Canadian Data Centers - AWS ca-central-1 region in Montreal
- Auto-Scaling - Automatically scales to handle peak demand
- Global CDN - Fast asset delivery worldwide via edge network
Uptime & Monitoring
- 99.5% Uptime SLA - Guaranteed availability for business-critical operations
- 24/7 Monitoring - Continuous system health monitoring around the clock
Backup & Recovery
- Automated Backups - Daily backups every 24 hours to protect your data
- Disaster Recovery - Documented procedures for rapid recovery
Third-Party Subprocessors
Third-party services we use to deliver AssetLab. All subprocessors are contractually bound to protect your data.
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database & Storage | Canada |
| Clerk | Authentication | USA |
| Resend | Transactional Email | USA |
| Cloudflare | CDN, Security & DNS | Global (Edge) |
Last updated: March 2026
Questions About Security?
Our security team is here to answer your questions and provide additional documentation for enterprise procurement and compliance reviews.
Responsible disclosure • Enterprise support • Compliance documentation