Security & Trust Center
Enterprise-Grade Security for Your Critical Asset Data
At AssetLab, security is fundamental. We've built our platform with enterprise-grade security, privacy-first design, and transparent practices to protect your asset information.
All legal documents
- Last updated
- August 9, 2026
Security & Data Protection
Multi-layered security architecture built for enterprise asset management. Your data is protected at every level.
Infrastructure Security
- Encryption in Transit - TLS 1.3 is negotiated with modern clients. TLS 1.2 is the floor, and TLS 1.1 and below are rejected.
- AES-256 at Rest - Database encryption via Supabase enterprise infrastructure
Application Security
- Row-Level Security - PostgreSQL RLS ensures complete data isolation
- Multi-Tenant Isolation - Organization-based data segregation
- Audit Logging - Authentication events, role assignments, API key issuance, OAuth grants, configuration changes and external API calls including reads. Reads made through the web interface by a signed-in user are not yet individually logged.
Access Management
- Role-Based Access Control - Administrator, Manager, Staff, and Requester roles
- SSO Support - Single Sign-On available for enterprise customers
Penetration Testing
We commission third-party penetration tests to validate our security controls and identify vulnerabilities before they can be exploited. The most recent test was conducted in May 2026. Customers and active evaluations can request the report under a mutual NDA.
- Third-Party Auditors - Tests performed by qualified external security firms
- Findings Tracked to Closure - Each finding carries a regression test that fails against the unfixed version, so a fix cannot silently regress
- NDA-Protected Reports - Full findings available to customers under NDA
Compliance & Standards
Meeting Canadian standards for data protection and privacy. Built with compliance in mind from day one.
PIPEDA Aligned
Built with Canadian privacy principles in mind.
- Privacy by Design - Security and privacy considered in every feature
- Transparent Handling - Clear documentation of data processing activities
- User Consent - Consent collected before gathering personal information
Data Residency
We state our residency position precisely rather than claiming that everything is in Canada. Customer Data - asset records, work orders, work requests, compliance records, projects, vendors, custom fields, attachments and audit logs - is hosted in Canada (AWS ca-central-1, Montreal), together with its backups.
Not every category of data resides in Canada. Specifically:
- Identity and authentication data is processed by Clerk in the United States. A thin mirror (user ID, name, business email, role) is stored in Canada so the application can enforce roles and write audit logs.
- Transactional email transits Resend in the United States, as does inbound message content where the optional email intake channel is enabled.
- Application error diagnostics are processed by Sentry in the United States. IP address, user agent and request URL capture are disabled and session replay is off.
- Application traffic traverses Cloudflare's global edge, where TLS is terminated for firewall inspection. No Customer Data is stored there.
- Canadian Privacy Laws - Subject to PIPEDA, Quebec Law 25 and provincial privacy legislation
Customers subject to a statutory data-residency or access-location requirement should raise it before contract so we can confirm the position in writing.
Data Processing Agreement
A Data Processing Agreement is available for customers who require formal documentation of how we process personal data on their behalf. It carries the EU Standard Contractual Clauses (Modules Two and Three), the UK International Data Transfer Addendum and a Swiss addendum, together with the technical and organizational measures and the authorized sub-processor list. Request a copy to include in your internal procurement or compliance review. The DPA is not self-executing and takes effect only on execution by both parties.
Request DPA →Privacy & Data Protection
Your data, your rights, our commitment. We believe in transparent data practices and user control.
Privacy Principles
- No Data Selling - We never sell, trade, or rent your data to third parties
- Minimal Collection - We only collect data necessary to provide our services
- Transparent Processing - Clear documentation of how we use your information
- User Control - You maintain full control over your data at all times
Your Data Rights (PIPEDA)
- Right to Access - Request a copy of all your personal information
- Right to Correction - Request corrections to inaccurate data
- Right to Deletion - Request deletion of your account and associated data
- Data Portability - Export your data in common formats (CSV, JSON)
Infrastructure & Reliability
Enterprise-grade infrastructure you can count on. Built for performance, designed for reliability.
Cloud Infrastructure
- Supabase Enterprise - PostgreSQL database with enterprise-grade reliability
- Canadian Data Centers - AWS ca-central-1 region in Montreal
- Auto-Scaling - Automatically scales to handle peak demand
- Global CDN - Fast asset delivery worldwide via edge network
Uptime & Monitoring
- 99.5% Availability SLA - A monthly availability commitment backed by service credits, available on Enterprise subscriptions where the order form incorporates the AssetLab Service Level Agreement. Availability for other subscription tiers is addressed in Section 9.1 of the Terms of Service, and no service credits apply.
- Continuous Monitoring - Application and REST API polled from multiple locations
- Public Status Page - Live uptime and incident history, open to everyone
- Maintenance Windows - Scheduled maintenance runs Tuesday and Saturday, 02:00-05:00 Pacific, with at least 72 hours' notice where it is expected to interrupt service
Backup & Recovery
- Automated Backups - Daily backups from the managed data tier. Point-in-time recovery is available from that provider and is not presently enabled, so the recovery point objective is up to 24 hours.
- Independent Offsite Copies - Nightly encrypted copies of the database and storage buckets, and a weekly identity export, to a separate provider in AWS ca-central-1. Archives are encrypted client-side before upload with a key held offline, so the storage provider holds ciphertext it cannot decrypt. Object-lock immutability means a credential compromise cannot destroy backup history.
- Disaster Recovery - Documented procedures for rapid recovery
- Customer-Initiated Export - Export your data at any time via the interface (CSV) or the API (JSON)
Third-Party Subprocessors
This is the published sub-processor list referenced by Section 8.7 of the Terms of Service, Section 5.1 of the Privacy Policy, and Annex 3 of the AssetLab Data Processing Agreement. Every sub-processor is bound by a written data processing agreement with obligations no less protective than those in our DPA, and AssetLab remains liable to customers for their acts and omissions.
See all 6subprocessors →Questions About Security?
Our security team is here to answer your questions and provide additional documentation for enterprise procurement and compliance reviews.
Responsible disclosure • Enterprise support • Compliance documentation