ASUME

Trust Center

Security Measures

Last updated: 8 September 2026

Introduction

This Security Measures document describes the technical and organisational measures maintained by ASUME B.V. (“ASUME,” “we,” “us,” or “our”) to protect the confidentiality, integrity, availability, and resilience of Customer Data, Processor Personal Data, Accounts, Workspaces, and the systems used to provide the Service.

These measures apply according to the nature, architecture, functionality, and risk of the relevant Service component. Not every measure is implemented identically across every system, provider, environment, or feature.

Where ASUME Processes Processor Personal Data on behalf of a Customer under the Data Processing Agreement (“DPA”), these Security Measures constitute the technical and organisational measures incorporated into Schedule 2 of the DPA.

ASUME may modify individual measures as technology, threats, architecture, providers, and security practices evolve, provided that the overall level of protection for Processor Personal Data is not materially reduced during the applicable Subscription Term.

Where there is a conflict concerning Processing governed by the DPA, the DPA applies in accordance with the order of precedence established in the Agreement.

Capitalised terms not defined in this document have the meanings given in the Terms of Service or DPA.

1. Security Principles

1.1. Risk-Based Security

ASUME implements and maintains technical and organisational measures designed to provide a level of security appropriate to the risks associated with the Service and the Processing performed through it.

In selecting and maintaining those measures, ASUME considers the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and the likelihood and severity of risks to Customers, Users, Data Subjects, systems, and information.

1.2. Security Objectives

ASUME’s security controls are designed to support the confidentiality, integrity, availability, and resilience of material systems and information.

Relevant objectives include preventing unauthorised access or disclosure, preserving data and system integrity, maintaining appropriate availability, supporting restoration following relevant technical or physical incidents, and periodically assessing the effectiveness of material security controls.

1.3. Defence in Depth

ASUME uses multiple technical and organisational controls across identity, applications, infrastructure, data, vendors, personnel, monitoring, AI systems, and incident response rather than relying on a single security mechanism.

1.4. No Absolute Security

No software, network, cloud service, AI system, integration, storage system, or transmission mechanism can be guaranteed to be completely secure.

ASUME maintains and improves its controls as the Service, architecture, threat environment, and applicable risks evolve.

2. Security Governance

2.1. Security Responsibility

ASUME assigns responsibility for information security, privacy-related security, infrastructure security, application security, access management, incident handling, vendor security, and other material security functions to authorised personnel.

At ASUME’s current scale, those responsibilities may be held directly by founders or other authorised personnel rather than by separate security departments.

2.2. Security Policies and Procedures

ASUME maintains internal policies, procedures, technical documentation, or operational practices appropriate to material areas of information security, including access control, data handling, incident response, vendor management, system changes, credentials and secrets, production operations, and security reporting.

2.3. Security Review of Material Changes

Material changes to systems, architecture, infrastructure, vendors, data flows, or functionality that may materially affect Customer Data, Processor Personal Data, or the security of the Service are subject to security consideration appropriate to the nature and risk of the change.

2.4. Periodic Review

ASUME periodically reviews material security measures and updates controls where reasonably necessary in response to identified risks, security events, architectural changes, technology changes, provider changes, legal requirements, or material changes to the Service.

3. Identity and Access Control

3.1. Least Privilege

Access to production systems, Customer Data, Processor Personal Data, credentials, and security-sensitive systems is restricted according to least-privilege and business-need principles.

3.2. Personnel Access

Personnel access to production systems is limited to authorised individuals who require access to perform their responsibilities.

Privileged or administrative access is restricted more narrowly than ordinary operational access.

3.3. Individual Accounts

ASUME uses individually attributable accounts for personnel access to material systems where supported by the relevant provider or system.

Shared privileged credentials are avoided where individual access mechanisms are reasonably available.

3.4. Authentication

ASUME applies authentication controls appropriate to the sensitivity of the relevant system.

Privileged or administrative access to material production, infrastructure, source-control, and cloud-management systems is protected by multi-factor authentication where the relevant provider supports individual MFA.

Non-interactive service identities, automated systems, and machine credentials are protected through credential, permission, and secret-management controls appropriate to their function.

3.5. Access Lifecycle

Personnel access is granted, modified, and revoked according to operational need.

Access is removed or adjusted when a person leaves ASUME, changes responsibilities, no longer requires the access, or where continued access would present an unacceptable security risk.

3.6. Production Access

Direct access to production databases, storage systems, or other systems containing Customer Data or Processor Personal Data is restricted to authorised personnel and systems.

Such access is used only where reasonably necessary for authorised Service operation, security, maintenance, troubleshooting, support, incident response, quality evaluation, or other purposes permitted under the Agreement and DPA.

3.7. Customer Access Controls

Customers are responsible for managing their Users, Administrators, Workspace permissions, authentication settings, connected systems, integration permissions, API keys, and other access controls made available through the Service.

4. Encryption, Credentials, and Secrets

4.1. Data in Transit

ASUME uses TLS or equivalent transport encryption for transmission of Customer Data and Processor Personal Data over public networks where supported by the applicable protocol and Service architecture.

4.2. Data at Rest

Material production databases, storage systems, and other infrastructure used to store Customer Data or Processor Personal Data are configured to use encryption-at-rest capabilities provided by the applicable infrastructure, database, or storage provider where supported by the relevant service.

4.3. Database and Service Connections

Connections to material databases, storage systems, infrastructure services, and other sensitive service components use encrypted transport where supported and appropriate to the relevant architecture.

4.4. Credentials and Secrets

Passwords, API keys, access tokens, signing secrets, provider keys, service credentials, and similar security-sensitive information are subject to access restrictions and are not intentionally exposed through ordinary Customer-facing interfaces.

4.5. Secret Access

Access to material production secrets is limited to authorised systems and personnel according to operational need.

4.6. Rotation and Revocation

Credentials, access tokens, API keys, or other secrets may be rotated, revoked, or replaced where reasonably necessary following personnel changes, suspected compromise, security incidents, provider changes, exposure, or other material risk.

5. Infrastructure and Network Security

5.1. Infrastructure Providers

ASUME uses established cloud, hosting, database, storage, observability, networking, and other infrastructure providers to operate the Service.

Material Subprocessors that Process Processor Personal Data are identified in ASUME’s Subprocessor List.

5.2. Secure Configuration

ASUME applies provider-native access restrictions and security controls appropriate to relevant production infrastructure, including controls over network exposure, administrative access, credentials, and service-to-service access.

The specific controls depend on the architecture and capabilities of the relevant infrastructure provider.

5.3. Environment Separation

ASUME maintains logical or technical separation between production and non-production environments appropriate to the architecture and risk of the relevant systems.

Production credentials and production Customer Data are not intentionally made available to non-production systems except where reasonably necessary for an authorised purpose and subject to appropriate access restrictions.

5.4. Administrative Interfaces

Access to infrastructure consoles, administrative interfaces, production databases, storage management, deployment systems, and similar sensitive systems is restricted to authorised personnel.

5.5. Infrastructure Maintenance

Systems and components within ASUME’s operational control are updated, patched, replaced, or otherwise remediated according to risk, severity, exploitability, provider availability, compatibility, and operational requirements.

5.6. Availability Monitoring

ASUME monitors material production systems, infrastructure, or provider health to support detection of availability failures, errors, degradation, and other operational issues.

5.7. Shared Infrastructure Responsibility

Where ASUME relies on third-party infrastructure providers, those providers may be responsible for physical facilities, hardware, core network infrastructure, managed database layers, storage layers, hypervisors, or other provider-controlled security functions under the applicable shared-responsibility model.

ASUME remains responsible for the controls assigned to ASUME under that model.

6. Application and Development Security

6.1. Secure Development

ASUME considers security throughout development and maintenance of the Service, including authentication, authorisation, data access, input handling, secrets, integrations, dependencies, APIs, error handling, and deployment.

6.2. Engineering Review

Material application and infrastructure changes are subject to engineering review appropriate to the nature and risk of the change.

Where independent peer review is not reasonably available because of the size of the engineering team, equivalent safeguards may include automated testing, structured self-review, staged deployment, post-deployment verification, or another control appropriate to the relevant change.

6.3. Authentication and Authorisation

Customer-facing applications and APIs enforce authentication and authorisation controls designed to restrict unauthorised access to Customer Workspaces, Service functionality, and information.

6.4. Input and Request Handling

ASUME uses validation, sanitisation, type controls, API constraints, permission checks, or other mechanisms appropriate to the relevant functionality to reduce risks arising from malformed, unauthorised, unexpected, or malicious inputs.

6.5. Application Vulnerabilities

ASUME maintains controls intended to reduce exposure to common web and application security risks, including unauthorised access, inappropriate privilege escalation, insecure input handling, credential exposure, and other material application-security weaknesses.

6.6. Dependencies

ASUME monitors or reviews material software dependencies and relevant security advisories for systems within its control.

Remediation is prioritised according to factors including severity, exploitability, exposure, affected systems, operational impact, and likelihood of exploitation.

6.7. Change and Deployment Controls

Material production changes are deployed through controlled engineering processes appropriate to the nature and risk of the change.

Relevant controls may include review, testing, restricted deployment permissions, change tracking, staged deployment, rollback capabilities, and post-deployment verification according to the relevant system and deployment method.

6.8. Error Handling

ASUME designs application and infrastructure error handling to reduce unnecessary exposure of credentials, secrets, Customer Data, internal implementation details, security controls, or other sensitive information.

7. Workspace and Data Protection

7.1. Workspace Separation

ASUME is designed to logically separate Customer Workspaces and restrict access to Customer Data according to Workspace membership, role, permissions, and Service configuration.

7.2. Cross-Customer Access

Application and access controls are designed to prevent Users from intentionally accessing information belonging to another Customer without authorisation.

7.3. Data Minimisation

ASUME seeks to limit the collection, Processing, storage, access, and disclosure of Customer Data and Processor Personal Data to information reasonably necessary for the relevant Service functionality, security, support, compliance obligation, or other authorised purpose.

7.4. Development, Testing, and Troubleshooting

Access to production Customer Data for development, testing, debugging, troubleshooting, or similar technical purposes is limited to circumstances where reasonably necessary.

Where feasible, ASUME prefers synthetic, non-production, minimised, de-identified, or otherwise less-sensitive information for such activities.

7.5. Logs and Diagnostics

ASUME seeks to avoid unnecessary inclusion of Customer content, credentials, and sensitive information in logs, traces, metrics, diagnostics, and monitoring systems.

Where limited Customer information is required for authorised operational or security purposes, access and retention are restricted according to the relevant purpose.

7.6. Retention and Deletion

Customer Data and Processor Personal Data are retained and deleted in accordance with the Agreement, the DPA, applicable product functionality, legal obligations, and ASUME’s retention and backup practices.

Where ASUME Processes Processor Personal Data solely on behalf of Customer, return and deletion are governed by the DPA.

Where ASUME independently Processes Personal Data as Controller, applicable retention practices are described in the Privacy Policy.

Deleted information may remain temporarily in protected backups until removed through the ordinary backup lifecycle, subject to the DPA and applicable law.

8. Logging, Monitoring, and Vulnerability Management

8.1. Logging

ASUME maintains logs appropriate to Service operation, security, reliability, troubleshooting, abuse prevention, and incident investigation.

Logs may include authentication activity, application events, infrastructure events, errors, security-relevant events, technical identifiers, User identifiers, IP addresses, Workspace metadata, and limited content where reasonably necessary for authorised purposes.

8.2. Log Access

Access to material production and security logs is restricted to authorised personnel and systems according to operational need.

8.3. Monitoring

ASUME uses monitoring and alerting mechanisms to support detection of material errors, system degradation, availability failures, suspicious activity, and other events relevant to Service operation or security.

8.4. Log Retention

Logs are retained for periods appropriate to operational, security, compliance, investigation, and legal needs and are not intended to be retained indefinitely.

8.5. Vulnerability Identification

ASUME uses risk-based processes to identify vulnerabilities affecting systems within its control.

These processes may include dependency monitoring, security advisories, automated scanning, code or engineering review, provider notifications, internal testing, and vulnerability reports received from Customers, researchers, vendors, or other third parties.

8.6. Vulnerability Risk Assessment

Identified vulnerabilities are assessed using factors including severity, exploitability, accessibility, affected data, exposure, likelihood of exploitation, available mitigations, and potential impact.

8.7. Remediation

ASUME prioritises remediation or mitigation of identified vulnerabilities according to assessed risk and the feasibility and operational impact of remediation.

8.8. Control Assessment

ASUME periodically reviews or assesses material security controls and updates them where reasonably necessary based on risk, incidents, architectural changes, provider changes, or other relevant information.

9. Availability, Backup, and Recovery

9.1. Availability and Resilience

ASUME maintains technical and organisational measures designed to support the availability and resilience of material production systems.

9.2. Backups and Recovery Mechanisms

Material production data stores are backed up or protected using database, storage, replication, snapshot, point-in-time recovery, or other provider-supported recovery mechanisms appropriate to the relevant system.

9.3. Backup Protection

Access to backups and recovery data is restricted through controls maintained by ASUME or the applicable infrastructure provider.

9.4. Backup Retention

Backup retention periods vary according to the relevant system, infrastructure provider, data category, Customer agreement, operational need, and recovery requirements.

9.5. Recovery

ASUME maintains processes designed to restore material systems or data following relevant failures, outages, corruption, accidental deletion, or other recovery scenarios.

9.6. Recovery Review and Testing

Backup and recovery mechanisms for material systems are periodically reviewed and, where appropriate, tested to verify that the relevant recovery procedures remain usable and effective.

9.7. Service Continuity

ASUME considers service continuity and recoverability in the architecture and operation of material systems, including through provider resilience capabilities, backups, recovery mechanisms, restricted access, monitoring, and incident-response procedures.

ASUME does not represent that it maintains a separately certified or independently audited business-continuity or disaster-recovery programme unless expressly stated in the Trust Center.

10. Incident Response

10.1. Incident Management

ASUME maintains procedures for identifying, reporting, triaging, investigating, containing, mitigating, remediating, and recovering from material security incidents.

10.2. Severity and Triage

Suspected incidents are assessed according to factors including affected systems, affected Customers, data sensitivity, unauthorised access, integrity impact, availability impact, exploitability, scope, and potential harm.

10.3. Containment and Recovery

ASUME may isolate systems, rotate credentials, revoke access, disable integrations, restrict functionality, modify infrastructure, preserve evidence, apply mitigations, or take other measures reasonably necessary to contain or remediate an incident.

10.4. Incident Documentation

Material incidents are documented where appropriate to support investigation, remediation, legal or regulatory obligations, Customer communication, and post-incident review.

10.5. Personal Data Breach Notification

Where a security incident constitutes a Personal Data Breach affecting Processor Personal Data, ASUME will notify the affected Customer without undue delay in accordance with the DPA.

10.6. Post-Incident Review

ASUME may perform a post-incident review following material incidents to identify corrective actions and improvements to systems, architecture, procedures, monitoring, access controls, or other relevant safeguards.

11. Personnel, Contractors, and Vendors

11.1. Confidentiality

Personnel and contractors who may access Customer Data, Processor Personal Data, production systems, security information, or ASUME Confidential Information are subject to confidentiality obligations appropriate to their role.

11.2. Access by Need

Personnel and contractors receive access only to systems and information reasonably necessary for authorised responsibilities.

11.3. Onboarding and Offboarding

ASUME maintains processes for granting, modifying, and revoking relevant system access when personnel or contractors join, change responsibilities, or leave.

11.4. Security Awareness

Personnel with access to material systems or information receive security guidance, instructions, or awareness appropriate to their responsibilities and the risks associated with the systems they use.

11.5. Vendor Assessment

ASUME evaluates material vendors and Subprocessors according to the risk of the services provided.

Relevant considerations may include data access, Processing purpose, hosting or Processing location, transfer mechanism, contractual safeguards, available security information, technical controls, service dependency, and operational risk.

11.6. Subprocessor Agreements

Where ASUME acts as Processor, Subprocessors that Process Processor Personal Data are subject to contractual requirements consistent with the DPA and applicable Data Protection Law.

11.7. Subprocessor Transparency

Material Subprocessors that Process Processor Personal Data are identified in ASUME’s Subprocessor List in accordance with the DPA.

11.8. Vendor Access

Vendor access to Customer Data or Processor Personal Data is limited to information and permissions reasonably necessary for the relevant service or functionality.

12. AI, Human Evaluation, and Untrusted Content Security

12.1. AI Systems

ASUME may use AI models, machine-learning systems, language models, retrieval systems, inference systems, search providers, classifiers, evaluation systems, and related technologies to provide company-understanding and other Service functionality.

12.2. Data Minimisation for AI Providers

ASUME seeks to limit information transmitted to AI model or related technology providers to prompts, context, instructions, Inputs, Outputs, or other information reasonably necessary for the applicable operation.

12.3. Model Training and Data Use

ASUME does not use Customer Data or Processor Personal Data, in its capacity as Processor, to train or fine-tune generally reusable ASUME or third-party AI models unless Customer expressly opts in or otherwise agrees in writing.

Model inference, context Processing, retrieval, security filtering, debugging, support, evaluation of a Customer request, fraud or abuse detection, and similar Service operations do not constitute reusable model Training solely because an AI system is involved.

Separate rules apply to Public Source Data, Customer-Controlled Source content, Derived Data, aggregated or anonymised information, and other information that ASUME may lawfully Process outside its role as Processor.

Those uses are governed by the Terms of Service, Privacy Policy, applicable rights and rights reservations, Customer settings where applicable, and applicable law.

Nothing in these Security Measures expands ASUME’s rights to use data beyond those provided by the Agreement or applicable law.

12.4. Model Providers

Where an AI model or related provider Processes Processor Personal Data on ASUME’s behalf, the provider is managed as a Subprocessor in accordance with the DPA and Subprocessor List.

12.5. Human Evaluation and Verification

ASUME may use authorised personnel or contractors to review limited samples of Service Outputs, evidence structures, assumptions, inference results, or related Processing records for purposes including quality evaluation, verification of the inference pipeline, troubleshooting, safety, security, and support where permitted by the Agreement and DPA.

Where such review involves Customer Data or Processor Personal Data, access is limited to information reasonably necessary for the authorised purpose and is subject to applicable confidentiality, least-privilege, and access-control requirements.

Human verification is a sampled quality-control mechanism. It does not mean that every Output has been manually reviewed, independently verified, approved, or certified by ASUME.

ASUME does not use Customer Data or Processor Personal Data accessed through such review to train or fine-tune generally reusable ASUME or third-party AI models unless the relevant Customer has expressly opted in or otherwise agreed in writing.

12.6. Untrusted Source Content

ASUME treats retrieved webpages, documents, Customer-authorised sources, integrations, user-supplied materials, and other externally supplied content as potentially untrusted input.

ASUME maintains controls appropriate to current Service functionality designed to reduce the ability of untrusted content to override trusted application instructions, obtain unauthorised access to credentials or secrets, access information belonging to another Customer, or directly cause unauthorised external actions.

ASUME continues to evaluate and strengthen these controls as AI, retrieval, tool-use, and agent functionality evolves.

12.7. Instruction and Content Boundaries

Where technically applicable, ASUME separates trusted application or system instructions from retrieved or user-supplied content and does not treat external source content as having the same authority as trusted system instructions solely because that content is processed by an AI model.

12.8. Credentials and Model Context

ASUME limits unnecessary exposure of credentials, API keys, secrets, internal security information, and other sensitive system information to model context and retrieved source content.

12.9. External Actions

Where ASUME makes functionality available that can perform external actions, the functionality is subject to security controls appropriate to the action and its potential consequences.

Depending on the functionality, such controls may include scoped credentials, permission boundaries, Customer configuration, confirmation mechanisms, execution limits, destination restrictions, or other safeguards.

Customers remain responsible for configuring and authorising external actions in accordance with the Agreement and any applicable feature-specific or Agent Terms.

13. Shared Responsibility and Security Reporting

13.1. Shared Responsibility

Security of the Service depends on both ASUME’s controls and Customer’s configuration and use of the Service.

13.2. Customer Responsibilities

Customers are responsible for protecting their credentials, Accounts, devices, browsers, networks, integrations, connected systems, API keys, authentication methods, Workspace settings, and User and Administrator permissions.

Customers are also responsible for promptly removing or restricting access when it is no longer authorised or necessary.

13.3. Customer Configuration

Customers are responsible for correctly configuring security and access features made available through their applicable plan or Workspace, including User permissions, Administrator permissions, authentication settings, integrations, connected-source permissions, API credentials, and access scopes.

13.4. Customer Data and Connected Sources

Customers are responsible for ensuring that Customer Data and connected information are appropriate for the Service and are submitted, uploaded, connected, or otherwise made available with sufficient rights, authority, permissions, and lawful basis as required by the Agreement and applicable law.

13.5. Incident Reporting

Customers should promptly notify ASUME if they know or reasonably suspect that an Account, Workspace, credential, API key, integration, connected source, or connected system has been compromised or accessed without authorisation.

13.6. Vulnerability Reports

Customers and security researchers may report suspected vulnerabilities to:

security@asume.ai

Where reasonably possible, reports should identify the affected system or endpoint, describe the issue and potential impact, and provide reproduction information that can be obtained safely and lawfully.

13.7. Authorised Security Testing

The availability of a security-reporting address does not by itself authorise security testing of ASUME systems.

Unless ASUME publishes a separate Vulnerability Disclosure Policy or provides written authorisation, researchers must not intentionally:

  • access, modify, delete, retain, export, or disclose Customer Data or other information they are not authorised to access;
  • access another Customer’s Workspace;
  • disrupt or materially degrade the Service;
  • conduct destructive testing;
  • conduct social engineering;
  • introduce malware or persistent access;
  • perform denial-of-service activity; or
  • bypass security controls for purposes unrelated to safely demonstrating the reported issue.

14. Assurance, Changes, and Contact

14.1. Compliance and Security Evidence

Where reasonably appropriate and subject to confidentiality, security, legal, and commercial restrictions, ASUME may make available security documentation or other information reasonably necessary to support Customer security and compliance reviews in accordance with the DPA.

14.2. Certifications and Independent Assessments

ASUME does not represent that it holds any certification, attestation, penetration-test report, independent audit, or other assurance that is not expressly identified as current in ASUME’s Trust Center.

Current assurance activities and their status are described in the Trust Center.

A planned, in-progress, or roadmap item does not constitute a current certification, audit, independent assessment, penetration test, or contractual security control.

14.3. Changes to Security Measures

ASUME may update these Security Measures to reflect changes in the Service, architecture, providers, technology, threats, security practices, applicable law, or Processing arrangements.

14.4. No Material Reduction

Where these Security Measures form part of the DPA, updates will not materially reduce the overall level of protection for Processor Personal Data during the applicable Subscription Term.

14.5. Contact

Questions concerning these Security Measures or suspected vulnerabilities may be sent to:

security@asume.ai

Privacy-related questions may be sent to:

privacy@asume.ai

Legal questions may be sent to:

legal@asume.ai

Full company and contact information for ASUME B.V. is available in ASUME’s Legal Notice.

© 2026 ASUME B.V.