ASUME

Trust Center

Data Security

How Customer Data and other production data are encrypted, backed up, and accessed. Classification labels and destruction certificates that are not yet published are listed separately.

Encryption in transit

Data in transit is encrypted using TLS or equivalent transport encryption for Customer Data and Processor Personal Data over public networks, where supported by the applicable protocol and Service architecture. Current practices are described in Security Measures.

ASUME follows encryption practices appropriate to the Service. A published inventory of every protocol version in use across every internal system is not independently verified.

Encryption at rest

Data at rest on production databases, storage systems, and other material infrastructure containing Customer Data or Processor Personal Data uses encryption-at-rest capabilities provided by the applicable infrastructure, database, or storage provider where configured. Current practices are described in Security Measures.

These controls apply to material production stores. A claim that every file on every device is encrypted to a named algorithm is not independently verified.

Backup and recovery

Material production data stores are backed up or protected using database, storage, replication, snapshot, or provider-supported recovery mechanisms. Access to backups is restricted, and retention varies by system and data category. Current practices are described in Security Measures.

A published schedule of restoration drills against named recovery-time and recovery-point objectives is still being formalized. Broader continuity work lives on BC/DR.

Credentials and secrets

Passwords, API keys, access tokens, credentials, signing secrets, provider keys, and similar security-sensitive information are subject to access restrictions and are not intentionally exposed through ordinary Customer-facing interfaces. Current handling is described in Security Measures.

Access to material production secrets is limited to authorised systems and personnel according to operational need. Credentials may be rotated or revoked after personnel changes, suspected compromise, or other material risk.

Access monitoring

Access to production systems, Customer Data, and Processor Personal Data is restricted according to least privilege and business need. Personnel receive access only to the systems and information they need for authorised responsibilities, as described in Security Measures.

Production logging and review practices support detection of suspicious behaviour and investigation of incidents, as described in Security Measures. A documented annual access-monitoring standard covering every system is still being formalized.

Data retention

ASUME retains and deletes Customer Data and Processor Personal Data according to the applicable agreement, the DPA, the Privacy Policy, product functionality, legal obligations, and the backup lifecycle. Security handling is described in Security Measures.

Retention periods vary by data category. A standalone retention standard that applies a single deletion calendar to every electronic and physical record is still being formalized.

Physical security

ASUME hosts the Service with established cloud and hosting providers. Those providers are responsible for physical facilities, hardware, and related site controls under the applicable shared-responsibility model, as described in Security Measures.

ASUME does not operate its own data-center campus. Listing physical security here is a description of inherited provider controls, not a claim that ASUME independently staffs guards, CCTV, or high-security areas.

File sensitivity classification

ASUME is defining how data is classified by sensitivity, business value, and legal requirements so that handling controls can match the information. Current data-minimisation and development/testing expectations are described in Security Measures.

Automatic mandatory labels on every file, and a published rule that confidential data never appears in non-production environments without exception approval, are still being built out and are not independently verified.

Certificates of destruction

Customer-facing certificates of destruction for decommissioned devices are a roadmap item. Listing them here is not a representation that a certified sanitization tool or a downloadable certificate is available today.

Until that artefact is published, disposal of company devices follows internal handling. Production data deletion follows the retention and backup practices in Security Measures.