Trust Center

Security, privacy and reliability you can verify.

Everything procurement, IT and security teams need to evaluate Asetavo — in plain English and technical detail. We state what’s in place honestly, and never claim certifications we don’t hold.

GDPR-readyCCPA / CPRASOC 2 — in progressTLS everywhereEncrypted at rest
SecurityPrivacyData ownership & portabilityAccess control & audit logsInfrastructure & hostingAvailability & backupsSubprocessorsResponsible disclosure

Security

Your asset data is encrypted, isolated per customer, and only reachable by the people you authorize.

Security overview
  • TLS in transit; encryption at rest across the platform
  • Multi-tenant isolation — one workspace can never read another’s data
  • HMAC-signed reader/device events (authentic, tamper-evident ingest)
  • Encryption keys stored outside the tenant database
  • Secure authentication with short-lived, revocable tokens

Privacy

We collect only what we need to run the service, never sell your data, and honor privacy rights under GDPR and CCPA/CPRA.

Privacy Policy
  • Lawful bases documented; consent-gated non-essential cookies
  • Data-subject / consumer rights: access, correction, deletion, portability
  • We do not sell or share personal information for cross-context advertising
  • International transfers covered by standard contractual clauses

Data ownership & portability

Your data is always yours. Export it anytime; we delete it on a defined schedule after you leave.

Data Processing Addendum
  • Full export to spreadsheet or via the REST API at any time
  • Defined post-termination retention then deletion / anonymization
  • No lock-in — your register, history and reports stay portable

Access control & audit logs

You control exactly who can see and do what, and every change is logged.

  • Role-based access control (RBAC), deny-by-default
  • Finance-sensitive fields protected separately
  • Revocable user and device access
  • Full, attributable audit trail of changes

Infrastructure & hosting

Asetavo runs on hardened, monitored infrastructure with clear separation between customers.

  • Isolated tenant databases; key store outside the tenant DB
  • Network hardening and least-privilege access
  • Data-residency options available on Enterprise

Availability & backups

We keep the service available and your data recoverable.

System Status
  • Automated daily backups with point-in-time recovery
  • Business-continuity and recovery procedures
  • Live service status published publicly

Subprocessors

We use a small set of vetted providers to run the service, each under data-protection contracts.

Request the subprocessor list
  • Categories: cloud hosting, email delivery, analytics, payment processing
  • Each bound by obligations no less protective than our DPA
  • Current list available on request; notice given before material changes

Responsible disclosure

Found a vulnerability? Tell us — we welcome good-faith security research.

security@asetavo.com
  • Report to security@asetavo.com
  • We investigate and remediate promptly and keep you informed
  • No legal action for good-faith research under our process
Compliance

Where we stand — stated honestly

We show real status and never imply a certification we don’t hold.

EU / UK GDPR· Ready
CCPA / CPRA· Ready
SOC 2· In progress

“Ready” means our practices follow the standard’s requirements. It is not a certification.

Questions from your security or procurement team?
Security: security@asetavo.com · Privacy: privacy@asetavo.com · Legal: legal@asetavo.com

Ready to account for every asset?

Tag, track and audit everything you own — from a handheld scanner to a boardroom report.

No card required · Live in a day · Simple USD pricing