Security controls
A summary of the technical measures in place across the platform. These are engineering measures, not a certification.
| Area | Measure |
|---|---|
| Data residency | Enforced at the platform level — compute and storage stay in the EU (see below). |
| Authentication | One-time-code (OTP) sign-in, no passwords to leak; optional TOTP two-factor on every account. |
| Session security | HttpOnly, Secure, SameSite=Strict session cookies; append-only session records; self-service session revocation. |
| Audit trail | Append-only audit log with a hash-chain integrity check; scan events are immutable. |
| Tenant isolation | Every data query is scoped to the owning tenant; scan compute is isolated per job. |
| Egress / SSRF | Outbound scan and intel traffic is restricted to public IPs with DNS-rebinding and metadata-endpoint guards. |
| Scan authorisation | Active scans require a legal-authority attestation and/or Domain Control Verification before dispatch — enforced server-side, no override. |
| AI output hygiene | PII scrubbing on agent output; findings without a reproducible proof-of-concept are labelled unconfirmed — never presented as confirmed. |
| Runner channel | Control-plane ↔ scan-runner traffic is HMAC-signed with a shared secret. |
| Encryption | TLS in transit; artifacts encrypted at rest in EU-jurisdiction object storage. |
Where your data lives (EU residency)
AssurePort is built EU-first. Scan data, reports and account records are processed and stored in the European Union.
| Component | Provider | Region |
|---|---|---|
| Relational database | Cloudflare D1 | Western Europe (WEUR) |
| Object storage (reports, artifacts) | Cloudflare R2 | EU jurisdiction |
| Scan compute | Fly.io Machines | Frankfurt (fra) |
| Transactional email | Resend | EU region |
| Edge / control plane | Cloudflare Workers | EU edge |
Where a sub-processor may transfer data outside the EU, the transfer is governed by Standard Contractual Clauses (see the sub-processor registry and DPA).
Sub-processor registry
The third parties that may process customer data on our behalf. The authoritative list with contractual detail is in DPA Appendix. We notify customers before adding a new sub-processor.
| Sub-processor | Purpose | Data | Region / basis |
|---|---|---|---|
| Cloudflare | Edge, database (D1), object storage (R2), queues | Account data, scan data, reports | EU (WEUR / EU jurisdiction) · SCC |
| Fly.io | Scan-runner compute | Transient scan targets & artifacts | EU (Frankfurt) · SCC |
| Anthropic | AI models powering the scan agents | Scan target data during analysis | SCC · data-processing terms |
| Polar.sh | Billing (Merchant of Record) | Billing / account email | SCC |
| Resend | Transactional email (OTP, reports) | Email address | EU region · SCC |
How we test ourselves
We sell offensive security testing, so we run our own engines against AssurePort and fix what they find. Security issues we identify internally are remediated and shipped through our normal release process; researchers can report anything they find via our disclosure policy.
- Health / status endpoints tightened to remove version and infrastructure disclosure.
- Egress hardening on the anonymous preview and intel paths (SSRF / DNS-rebind defences).
- Session-handling fixes so a valid session is never dropped on a transient backend error.
- A claims-governance review to keep every result in evidence/readiness language — no unaccredited compliance attestations.
A third-party, independent security audit is on our roadmap (target Q4 2026–Q2 2027). We will publish its status here.
Compliance posture — what we claim, honestly
We are deliberate about the difference between measures we take, frameworks we align to, and certifications we hold. Today we hold no third-party security certification, and we say so.
| Framework | Status | What it means |
|---|---|---|
| GDPR | Measures in place | EU data residency, DPA with every customer, append-only audit log, 72-hour breach-notification SLA. Not a self-certification. |
| ISO 27001 | Aligned | Controls designed to align with Annex A. We are not ISO 27001 certified. |
| SOC 2 Type II | Roadmap 2026 | Mapping work planned for 2026. No audit is currently in progress. |
| PCI DSS | ASV-aligned scan | Our external vulnerability scan is aligned to ASV methodology. AssurePort is not a PCI SSC Approved Scanning Vendor and this does not replace a scan by a listed ASV. |
| NIS2 / DORA | Evidence mapping | Findings map to control evidence (NIS2 Art. 21, DORA Art. 24) to support your readiness work — we do not certify your compliance. |
Documents & requests
- Data Processing Addendum (GDPR Art. 28) — email legal@assureport.com with your legal entity name; we countersign within one business day.
- Privacy Policy · Terms of Service · Cookie Policy
- Security disclosure policy · security.txt
- A DPIA summary is available to customers under NDA — contact dpo@assureport.com.
- Security or vulnerability reports: abuse@assureport.com.