ASUME

Trust Center

Risk Management

How ASUME identifies and treats security, vendor, and operational risk. Formal risk-register work is still being built out and is not independently verified.

Data access and impact levels

We classify information assets, assess associated risks, and apply controls proportional to their impact. Access follows least privilege and role-based access control (RBAC), as described in Security Measures.

A documented mapping of data-access and impact levels is still being formalized. Until it is published, resources stay focused on protecting the most sensitive information while keeping the Service operable.

Risk assessments

ASUME is building a continuous risk-management process designed to protect the Service and Customer Data. Reviews are led by the people who operate the product and infrastructure today; dedicated Information Security and Risk teams are not yet in place.

Identified risks are recorded and treated until they are reduced to an acceptable level. A formal annual cycle and an independently verified register are still being built out.

Supply-chain risk management

Security controls for third-party relationships are defined in Security Measures and the Data Processing Agreement, including Subprocessor engagement. New vendors are reviewed before they can process Customer Data.

Periodic reassessment of vendor security posture, including at contract renewal, is still being built. Oversight today is shared across the people who handle procurement, security, and legal review.

Business impact assessment

A formal annual Business Impact Analysis (BIA) is a roadmap item. When it is in place, it will identify the most critical functions of the Service, the effect of a disruption, and dependencies on applications and vendors.

Until that analysis is documented, continuity and resilience work remains informal and is not independently verified.

Risk Management Standard

A standalone Risk Management Standard — the formal process for protecting the confidentiality, integrity, and availability of the Service and Customer Data — is still being drafted.

Until it is published, current handling lives in Security Measures. The eventual standard is intended to cover company information systems, assets, and their users, including employees, contractors, and relevant third-party vendors, and to be reviewed annually or after a major change in people, process, or technology.