Trust Center

Everything a security or procurement team needs to evaluate AssurePort — our controls, where your data lives, who processes it, how we test ourselves, and exactly what we do and do not claim. We describe measures and evidence, not guarantees.

Security controls

A summary of the technical measures in place across the platform. These are engineering measures, not a certification.

AreaMeasure
Data residencyEnforced at the platform level — compute and storage stay in the EU (see below).
AuthenticationOne-time-code (OTP) sign-in, no passwords to leak; optional TOTP two-factor on every account.
Session securityHttpOnly, Secure, SameSite=Strict session cookies; append-only session records; self-service session revocation.
Audit trailAppend-only audit log with a hash-chain integrity check; scan events are immutable.
Tenant isolationEvery data query is scoped to the owning tenant; scan compute is isolated per job.
Egress / SSRFOutbound scan and intel traffic is restricted to public IPs with DNS-rebinding and metadata-endpoint guards.
Scan authorisationActive scans require a legal-authority attestation and/or Domain Control Verification before dispatch — enforced server-side, no override.
AI output hygienePII scrubbing on agent output; findings without a reproducible proof-of-concept are labelled unconfirmed — never presented as confirmed.
Runner channelControl-plane ↔ scan-runner traffic is HMAC-signed with a shared secret.
EncryptionTLS in transit; artifacts encrypted at rest in EU-jurisdiction object storage.

Where your data lives (EU residency)

AssurePort is built EU-first. Scan data, reports and account records are processed and stored in the European Union.

ComponentProviderRegion
Relational databaseCloudflare D1Western Europe (WEUR)
Object storage (reports, artifacts)Cloudflare R2EU jurisdiction
Scan computeFly.io MachinesFrankfurt (fra)
Transactional emailResendEU region
Edge / control planeCloudflare WorkersEU edge

Where a sub-processor may transfer data outside the EU, the transfer is governed by Standard Contractual Clauses (see the sub-processor registry and DPA).

Sub-processor registry

The third parties that may process customer data on our behalf. The authoritative list with contractual detail is in DPA Appendix. We notify customers before adding a new sub-processor.

Sub-processorPurposeDataRegion / basis
CloudflareEdge, database (D1), object storage (R2), queuesAccount data, scan data, reportsEU (WEUR / EU jurisdiction) · SCC
Fly.ioScan-runner computeTransient scan targets & artifactsEU (Frankfurt) · SCC
AnthropicAI models powering the scan agentsScan target data during analysisSCC · data-processing terms
Polar.shBilling (Merchant of Record)Billing / account emailSCC
ResendTransactional email (OTP, reports)Email addressEU region · SCC

How we test ourselves

We sell offensive security testing, so we run our own engines against AssurePort and fix what they find. Security issues we identify internally are remediated and shipped through our normal release process; researchers can report anything they find via our disclosure policy.

Recent hardening shipped. A sample of internally-identified issues we have found and remediated:
  • Health / status endpoints tightened to remove version and infrastructure disclosure.
  • Egress hardening on the anonymous preview and intel paths (SSRF / DNS-rebind defences).
  • Session-handling fixes so a valid session is never dropped on a transient backend error.
  • A claims-governance review to keep every result in evidence/readiness language — no unaccredited compliance attestations.

A third-party, independent security audit is on our roadmap (target Q4 2026–Q2 2027). We will publish its status here.

Compliance posture — what we claim, honestly

We are deliberate about the difference between measures we take, frameworks we align to, and certifications we hold. Today we hold no third-party security certification, and we say so.

FrameworkStatusWhat it means
GDPRMeasures in placeEU data residency, DPA with every customer, append-only audit log, 72-hour breach-notification SLA. Not a self-certification.
ISO 27001AlignedControls designed to align with Annex A. We are not ISO 27001 certified.
SOC 2 Type IIRoadmap 2026Mapping work planned for 2026. No audit is currently in progress.
PCI DSSASV-aligned scanOur external vulnerability scan is aligned to ASV methodology. AssurePort is not a PCI SSC Approved Scanning Vendor and this does not replace a scan by a listed ASV.
NIS2 / DORAEvidence mappingFindings map to control evidence (NIS2 Art. 21, DORA Art. 24) to support your readiness work — we do not certify your compliance.

Documents & requests

Need something not listed here? Security questionnaires, architecture detail, or a specific control mapping — email dpo@assureport.com and you will reach the founder directly.