Security, Compliance & Assurance
Independent standards. Verifiable controls.
- ISO/IEC 27001 Certified Information Security Management System
- SOC 2 Type II Attested
- CSA STAR Registered
Security and Compliance You Can Verify
Assai is committed to maintaining a mature, transparent, and demonstrable security and compliance posture for its SaaS platform.
We support organizations that manage sensitive engineering and asset information, operate in regulated environments, and require clear assurance of vendor security maturity. Our compliance framework is built on internationally recognized standards and independent assessments, not self-asserted claims.
Our Compliance Framework
Assai’s compliance framework rests on three pillars: an information security management system certified to ISO/IEC 27001:2022/AMD1:2024, a SOC 2 Type II attestation, and public CSA STAR disclosures.
ISO/IEC 27001
Certified information security management system
SOC 2 Type II
Independent assurance over operational controls
CSA STAR
Transparent cloud security disclosures
Assai combines internationally recognised certification, independent assurance and transparent security disclosures to help customers satisfy enterprise procurement, security review and regulatory requirements.
ISO/IEC 27001 Certified Information Security Management
Assai’s Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022/AMD1:2024 by DigiTrust, an independent certification body accredited by the Dutch Accreditation Council (RvA).
The certified ISMS provides a structured, independently audited framework for identifying and managing information security risks, protecting customer information, and continually improving security controls.
Certification scope
Information Security related to the design, development, delivery, and support of the Assai Suite software platform (SaaS), including the information security processes, infrastructure, locations, and controls supporting its operation.
SOC 2 Type II Attestation
Assai adheres to a SOC 2 Type II Attestation report, providing assurance over the design and operating effectiveness of security controls over time.
SOC 2 is an internationally recognized standard developed by the American Institute of Certified Public Accountants (AICPA). It evaluates services provided by a service organization so that customers can assess and address risks associated with outsourced cloud services.
Assai’s SOC 2 assessment covers the following Trust Services Criteria:
Security
Protection of systems and data against unauthorized access
Availability
Systems are accessible and operational as committed
Confidentiality
Restriction of access to sensitive systems and data
SOC 2 adapts to the nature and needs of each organization. Assai has designed its controls to reflect the risks and requirements associated with cloud-based document and data management in engineering-driven environments.
SOC 2 Type I vs. Type II
There are two types of SOC 2 reports:
- Type I
Assesses whether controls are suitably designed at a specific point in time. - Type II
Assesses whether those controls operate effectively over a defined period.
Assai has obtained a SOC 2 Type II Attestation, providing a higher level of assurance through continuous operational validation.
The SOC 2 Type II report is available to customers and prospects under NDA.
Transparency Through CSA STAR
In addition to formal attestations, Assai publishes its cloud security controls in the Cloud Security Alliance (CSA) STAR Registry – Level 1.
The CSA is a globally recognized, industry-led organization that defines best-practice security controls for cloud services. The STAR Registry enables customers to assess cloud providers using a standardized, independent framework rather than relying solely on vendor statements.
Assai’s CSA STAR disclosures cover:
By making these controls publicly available, customers and partners can clearly understand how Assai governs security, risk management, and compliance across its SaaS platform.
How We Protect Critical Engineering Information
Two-Factor Authentication (2FA)
Assai supports Two-Factor Authentication (2FA) to provide an additional layer of protection for user access.
Combined with role-based access controls, 2FA helps ensure that only authorized users can access sensitive resources.
Assai uses Cloudflare to provide network- and application-level security and performance protection.
This includes:
DDoS protection to mitigate large-scale attacks
Web Application Firewall (WAF) to protect against common web threats
These controls strengthen perimeter security and improve overall platform resilience. Together, they help ensure the security, resilience, and availability of critical engineering data.
Security is embedded throughout our Software Development Lifecycle (SDLC).
We follow the Microsoft Secure Development Lifecycle (SDL) methodology, integrating security controls across all development phases.
To ensure platform reliability and business continuity, we implement:
- Disaster Recovery (DR) testing for system resilience
- Continuous monitoring to detect and respond to threats in real time
- Secure data management across the full data lifecycle
These practices help ensure systems remain operational even under adverse conditions.