Security, Compliance & Assurance

Independent standards. Verifiable controls.

Security and Compliance You Can Verify

Assai is committed to maintaining a mature, transparent, and demonstrable security and compliance posture for its SaaS platform.

We support organizations that manage sensitive engineering and asset information, operate in regulated environments, and require clear assurance of vendor security maturity. Our compliance framework is built on internationally recognized standards and independent assessments, not self-asserted claims.

Our Compliance Framework

Assai’s compliance framework rests on three pillars: an information security management system certified to ISO/IEC 27001:2022/AMD1:2024, a SOC 2 Type II attestation, and public CSA STAR disclosures.

ISO/IEC 27001

Certified information security management system

SOC 2 Type II

Independent assurance over operational controls

CSA STAR

Transparent cloud security disclosures

Assai combines internationally recognised certification, independent assurance and transparent security disclosures to help customers satisfy enterprise procurement, security review and regulatory requirements.

ISO/IEC 27001 Certified Information Security Management

Assai’s Information Security Management System (ISMS) is certified to ISO/IEC 27001:2022/AMD1:2024 by DigiTrust, an independent certification body accredited by the Dutch Accreditation Council (RvA).

The certified ISMS provides a structured, independently audited framework for identifying and managing information security risks, protecting customer information, and continually improving security controls.

Certification scope

Information Security related to the design, development, delivery, and support of the Assai Suite software platform (SaaS), including the information security processes, infrastructure, locations, and controls supporting its operation.

ISO 27001 compliance certification badge for DigiTrust, indicating adherence to information security management standards; includes RvA accreditation.

SOC 2 Type II Attestation

Assai adheres to a SOC 2 Type II Attestation report, providing assurance over the design and operating effectiveness of security controls over time.


SOC 2 is an internationally recognized standard developed by the American Institute of Certified Public Accountants (AICPA). It evaluates services provided by a service organization so that customers can assess and address risks associated with outsourced cloud services.


Assai’s SOC 2 assessment covers the following Trust Services Criteria:

Security

Protection of systems and data against unauthorized access

Availability

Systems are accessible and operational as committed

Confidentiality

Restriction of access to sensitive systems and data

SOC 2 adapts to the nature and needs of each organization. Assai has designed its controls to reflect the risks and requirements associated with cloud-based document and data management in engineering-driven environments.

SOC 2 Type I vs. Type II​

There are two types of SOC 2 reports:

  • Type I
    Assesses whether controls are suitably designed at a specific point in time.
  • Type II
    Assesses whether those controls operate effectively over a defined period.

Assai has obtained a SOC 2 Type II Attestation, providing a higher level of assurance through continuous operational validation.

The SOC 2 Type II report is available to customers and prospects under NDA.

Transparency Through CSA STAR​

In addition to formal attestations, Assai publishes its cloud security controls in the Cloud Security Alliance (CSA) STAR Registry – Level 1.

The CSA is a globally recognized, industry-led organization that defines best-practice security controls for cloud services. The STAR Registry enables customers to assess cloud providers using a standardized, independent framework rather than relying solely on vendor statements.

Assai’s CSA STAR disclosures cover:

By making these controls publicly available, customers and partners can clearly understand how Assai governs security, risk management, and compliance across its SaaS platform.

How We Protect Critical Engineering Information

Identity & Access

Two-Factor Authentication (2FA)

Assai supports Two-Factor Authentication (2FA) to provide an additional layer of protection for user access.

Combined with role-based access controls, 2FA helps ensure that only authorized users can access sensitive resources.

Infrastructure Protection

Assai uses Cloudflare to provide network- and application-level security and performance protection.

This includes:

  • DDoS protection to mitigate large-scale attacks

  • Web Application Firewall (WAF) to protect against common web threats

These controls strengthen perimeter security and improve overall platform resilience. Together, they help ensure the security, resilience, and availability of critical engineering data.

Secure Development

Security is embedded throughout our Software Development Lifecycle (SDLC).

We follow the Microsoft Secure Development Lifecycle (SDL) methodology, integrating security controls across all development phases.

Monitoring & Resilience

To ensure platform reliability and business continuity, we implement:

  • Disaster Recovery (DR) testing for system resilience
  • Continuous monitoring to detect and respond to threats in real time
  • Secure data management across the full data lifecycle


These practices help ensure systems remain operational even under adverse conditions.