Security, privacy and reliability you can verify.
Everything procurement, IT and security teams need to evaluate Asetavo — in plain English and technical detail. We state what’s in place honestly, and never claim certifications we don’t hold.
Security
Your asset data is encrypted, isolated per customer, and only reachable by the people you authorize.
Security overview →- TLS in transit; encryption at rest across the platform
- Multi-tenant isolation — one workspace can never read another’s data
- HMAC-signed reader/device events (authentic, tamper-evident ingest)
- Encryption keys stored outside the tenant database
- Secure authentication with short-lived, revocable tokens
Privacy
We collect only what we need to run the service, never sell your data, and honor privacy rights under GDPR and CCPA/CPRA.
Privacy Policy →- Lawful bases documented; consent-gated non-essential cookies
- Data-subject / consumer rights: access, correction, deletion, portability
- We do not sell or share personal information for cross-context advertising
- International transfers covered by standard contractual clauses
Data ownership & portability
Your data is always yours. Export it anytime; we delete it on a defined schedule after you leave.
Data Processing Addendum →- Full export to spreadsheet or via the REST API at any time
- Defined post-termination retention then deletion / anonymization
- No lock-in — your register, history and reports stay portable
Access control & audit logs
You control exactly who can see and do what, and every change is logged.
- Role-based access control (RBAC), deny-by-default
- Finance-sensitive fields protected separately
- Revocable user and device access
- Full, attributable audit trail of changes
Infrastructure & hosting
Asetavo runs on hardened, monitored infrastructure with clear separation between customers.
- Isolated tenant databases; key store outside the tenant DB
- Network hardening and least-privilege access
- Data-residency options available on Enterprise
- Automated daily backups with point-in-time recovery
- Business-continuity and recovery procedures
- Live service status published publicly
Subprocessors
We use a small set of vetted providers to run the service, each under data-protection contracts.
Request the subprocessor list →- Categories: cloud hosting, email delivery, analytics, payment processing
- Each bound by obligations no less protective than our DPA
- Current list available on request; notice given before material changes
Responsible disclosure
Found a vulnerability? Tell us — we welcome good-faith security research.
security@asetavo.com →- Report to security@asetavo.com
- We investigate and remediate promptly and keep you informed
- No legal action for good-faith research under our process
Where we stand — stated honestly
We show real status and never imply a certification we don’t hold.
“Ready” means our practices follow the standard’s requirements. It is not a certification.
Ready to account for every asset?
Tag, track and audit everything you own — from a handheld scanner to a boardroom report.
No card required · Live in a day · Simple USD pricing