ASUME

Trust Center

Infrastructure

Hosting providers, regions, environment separation, and inherited network protections. A public status page is still being built out and is not independently verified.

Cloud service providers

ASUME partners with established cloud and hosting providers to operate the Service. Current designated workloads include AWS infrastructure in the United States, Hetzner in Germany, and a European Supabase project region. Feature-dependent providers may process data in additional locations listed on the Subprocessor List.

Provider selection is intended to support redundancy and availability for material systems. Listing a provider here is not a representation that ASUME holds that provider's certifications.

Data locations

Processing locations for each Subprocessor, including any onward processing, are identified on the Subprocessor List. The selected region determines the primary location of the relevant Customer workload.

Customers should review the Subprocessor List for the current locations applicable to the features they use.

Hosting regions

The selected region determines the primary location of the relevant Customer workload. Processing locations for each Subprocessor are identified on the Subprocessor List.

Region choice does not remove the possibility of feature-dependent processing in additional locations disclosed on that list.

Separate production environment

ASUME maintains separation between production and non-production environments to the extent supported by the relevant architecture and operational requirements, as described in Security Measures.

Access to production Customer Data for development, testing, debugging, or troubleshooting is limited to circumstances where reasonably necessary, with preference given to non-production, synthetic, minimised, or otherwise less-sensitive information where feasible. See Security Measures.

Network Time Protocol

ASUME relies on provider and operating-system time synchronization (NTP or equivalent) so that clocks on servers and network devices stay aligned for logging, authentication, and operational correlation.

A published company-wide NTP architecture document is not independently verified. Treat this as an operational baseline, not a separately attested time service.

Anti-DDoS

Internet-facing production services rely on DDoS protections offered by ASUME's cloud and hosting providers. Provider-level network restrictions and related infrastructure controls are described in Security Measures.

ASUME does not publish a standalone anti-DDoS product name or mitigation runbook. Listing this control describes inherited provider protection, not an independently verified in-house service.

Status monitoring

ASUME monitors material production systems, infrastructure, or provider health to support detection of availability failures, errors, degradation, or other operational issues, as described in Security Measures.

A public status page that customers can check independently is still being built out and is not independently verified. Until it is published, treat the internal monitoring described in Security Measures as the current baseline.