ASUME

Trust Center

Security & Compliance Roadmap

Items ASUME intends to pursue. They are listed here, not beside current documentation, so they cannot be read as certifications or current compliance claims.

Near-term

Independent penetration test

Third-party assessment of the production Service, remediation of material findings, and availability of an executive summary for qualified customers.

Formal vulnerability disclosure program

Documented scope, safe-harbour expectations, reporting procedure, triage and remediation workflow.

Formalised security control register

Internal mapping of ASUME controls, owners, evidence, review cycles, and risk treatment.

Data-flow and system architecture assurance documentation

Customer-facing versions of data-flow and architecture documentation for security review.

Next stage

ISO/IEC 27001 readiness

Development of an Information Security Management System and gap assessment against ISO/IEC 27001:2022.

Independent ISO/IEC 27001 certification

Subject to completion of readiness work and independent certification assessment.

SOC 2 readiness

Evaluation and implementation of controls required for an independent SOC 2 examination, with timing driven in part by customer requirements.

AI governance framework

Formalisation of AI risk ownership, model/provider diligence, evaluation, security controls, incident handling and regulatory role assessments.

Longer term

ISO/IEC 42001

Potential AI management-system certification as ASUME's AI governance program and enterprise requirements mature.

SOC 2 Type II

Independent assessment over an operating period once the underlying control environment and evidence collection are mature.

© 2026 ASUME B.V.