Security & compliance

Security you can build on.

Multi-tenant isolation, encryption everywhere, revocable access and signed device events — from day one. Here’s how Asetavo keeps your asset data secure and compliant.

GDPR-readySOC 2 (roadmap)TLS everywhere

Tenant isolation

Every workspace is isolated so one tenant can never reach another’s data.

Encryption at rest & in transit

TLS everywhere, and data encrypted at rest across the platform.

Revocable tokens

API and device tokens are scoped and can be rotated or revoked at any time.

Signed device events

Reader events are HMAC-signed so ingested data is authentic and tamper-evident.

How tenant isolation works

Tenant A
Isolated tenant DB
Key store (outside tenant DB)
Reader event (signed)

Access control / RBAC

Fine-grained roles across capabilities, deny-by-default, with finance fields protected separately.

Data ownership, export & deletion

Your data is yours — export anytime, and it is deleted on a defined schedule after termination.

Backups & availability

Automated daily backups with point-in-time recovery; see System Status for uptime.

Hosting & data residency

Currently hosted in shared regions; dedicated data-residency options are on the roadmap.

Compliance status & roadmap

GDPR-ready
SOC 2 — in progress
Responsible disclosure
Found a vulnerability? Report it to security@asetavo.com
FAQ

Security questions, answered

Yes. Asetavo encrypts data in transit with TLS and at rest across the platform, and keys are stored separately from tenant databases.

Ready to account for every asset?

Tag, track and audit everything you own — from a handheld scanner to a boardroom report.

No card required · Live in a day · TZS/USD/GBP