Trust

Security at Assetriq

Assetriq handles sensitive property, client and financial data. This page describes the controls we have in place today. We do not claim certifications we do not hold.

Data protection

  • All traffic is encrypted in transit with TLS 1.2+.
  • All data at rest is encrypted with AES-256 by our infrastructure providers.
  • Authentication uses short-lived session tokens; passwords are hashed with bcrypt.

Hosting and data residency

Application and database infrastructure is hosted in EU/EEA data centres. Object storage for uploaded documents can be pinned to Switzerland on request for eligible plans.

Access control

  • Row-level security is enforced at the database layer for every tenant table.
  • Engineering access to production is limited to named individuals, audit-logged, and reviewed quarterly.
  • Customer admins control their own team membership and roles.

Backups and disaster recovery

Databases are backed up daily with point-in-time recovery for the last 7 days. Recovery procedures are tested periodically. Target RPO 24h, target RTO 8h.

Responsible disclosure

Report suspected vulnerabilities to security@assetriq.com. We respond within 3 business days and do not pursue legal action against good-faith researchers.

What we do not claim

Assetriq is not currently SOC 2, ISO 27001 or HIPAA certified. Formal certification is on our roadmap; ask your account contact for current status.

Last updated: 4 August 2026. Questions? trust@assetriq.com