Independent penetration test
Third-party assessment of the production Service, remediation of material findings, and availability of an executive summary for qualified customers.
Trust Center
Items ASUME intends to pursue. They are listed here, not beside current documentation, so they cannot be read as certifications or current compliance claims.
Third-party assessment of the production Service, remediation of material findings, and availability of an executive summary for qualified customers.
Documented scope, safe-harbour expectations, reporting procedure, triage and remediation workflow.
Internal mapping of ASUME controls, owners, evidence, review cycles, and risk treatment.
Customer-facing versions of data-flow and architecture documentation for security review.
Development of an Information Security Management System and gap assessment against ISO/IEC 27001:2022.
Subject to completion of readiness work and independent certification assessment.
Evaluation and implementation of controls required for an independent SOC 2 examination, with timing driven in part by customer requirements.
Formalisation of AI risk ownership, model/provider diligence, evaluation, security controls, incident handling and regulatory role assessments.
Potential AI management-system certification as ASUME's AI governance program and enterprise requirements mature.
Independent assessment over an operating period once the underlying control environment and evidence collection are mature.