Legal
Security
AssetStack was built for organisations that manage critical infrastructure, where a data breach, system outage or compliance failure is not merely a commercial risk, but a safety and reputational risk. Our security architecture reflects that reality.
Infrastructure and Data Residency
Australian Data Residency
All Customer Data is stored in Australian data centres. We do not offshore primary data storage, processing or backups to international jurisdictions. Your data stays in Australia.
Cloud Infrastructure
Our platform operates on enterprise-grade cloud infrastructure with physically secured facilities, redundant power, environmental controls and 24/7 monitoring.
Encryption
Encryption in Transit
All data transmitted between Users and the AssetStack platform is encrypted using TLS 1.2 or higher. API communications require authenticated, encrypted connections.
Encryption at Rest
All stored Customer Data is encrypted at rest using AES-256 encryption. Encryption keys are managed through secure key management infrastructure with strict access controls.
Access Control
Role-Based Access Control (RBAC)
Granular permission structures allow Customers to define who can view, edit, approve or export data. Roles include full access, client-scoped, view-only, contractor and auditor.
Multi-Factor Authentication (MFA)
Enforced for all administrative accounts and available for all Users. MFA is required for password resets and sensitive configuration changes.
Single Sign-On (SSO)
Enterprise SSO integration via SAML 2.0 for centralised identity management and access provisioning.
Data Isolation
Per-Tenant Isolation
Customer data is logically isolated at the database and application layers. No cross-tenant data visibility exists, even at the infrastructure level. Each Customer's data is sandboxed within its own secure partition.
Monitoring and Logging
Audit Trails
Every action within the platform is logged with timestamp, user identity, IP address and action detail. Logs include: logins, data exports, configuration changes, prediction retrains, savings entries and inspection uploads.
Security Monitoring
Continuous automated monitoring of infrastructure for anomalous access patterns, failed authentication attempts and potential security threats. Alerts are escalated to our security team in real time.
Compliance and Certifications
| Standard | Status |
|---|---|
| SOC 2 Type II | In progress |
| ISO 27001 | Aligned with full implementation underway |
| Privacy Act 1988 (Cth) | Compliant. Australian Privacy Principles |
| Australian Data Residency | Enforced. All primary data stored in Australia |
Incident Response
Detection and Response
Defined incident response procedures with clear escalation paths, containment protocols and communication plans. Security incidents are investigated, documented and remediated according to a documented playbook.
Customer Notification
In the event of a data breach affecting Customer Data, we will notify affected Customers without undue delay and in accordance with our obligations under the Privacy Act 1988 (Cth) and applicable notifiable data breach schemes.
Vulnerability Management
Regular Assessments
Security assessments, penetration testing and vulnerability scanning are conducted regularly by internal teams and independent third parties.
Patch Management
Critical security patches are applied within 48 hours of release. Non-critical patches are applied within scheduled maintenance windows.
Third-Party Security
All third-party service providers with access to our infrastructure or Customer Data are subject to:
- security due diligence before engagement
- contractual confidentiality and security obligations
- regular review of their security practices
Your Responsibilities
While AssetStack secures the platform, Customers are responsible for:
- maintaining strong, unique passwords and enabling MFA
- managing User access and promptly revoking access for departing staff
- classifying and managing their own data appropriately
- ensuring uploaded content does not contain malicious code
Contact
For security inquiries, vulnerability reports or incident notification:
Email: [email protected]
