Skip to main content

OUR COMMITMENT TO PROTECTING YOUR DATA

Trust Center

Security, transparency, and accountability

Everything you need to learn about AssureSoft’s  approach to information security and data protection.

CERTIFICATIONS

Backed by internationally recognized standards

Our certifications provide independent validation that our security practices meet rigorous global benchmarks.

ISO/IEC 27001:2022

Active

AssureSoft is certified to ISO/IEC 27001:2022 by TÜV Rheinland of North America. This certification covers software development, quality control, project management, and IT service support.

View certification

SOC 2 Type II 

In Progress

AssureSoft is currently undergoing a SOC 2 Type II audit to assess the effectiveness of our security and confidentiality controls over time.

How does AssureSoft review and improve its security controls?

AssureSoft reviews and improves its security controls through ongoing risk management, compliance activities, incident analysis, and continuous improvement processes aligned with its ISO/IEC 27001:2022-certified Information Security Management System. This includes governance, operational security, data protection, vendor security, and incident response practices.

What does ISO/IEC 27001 certification mean in practice for software partnerships?

ISO/IEC 27001 certification provides independent validation that AssureSoft operates under a structured Information Security Management System covering governance, operational security, risk management, incident response, and continuous improvement practices.

How does AssureSoft maintain alignment with evolving security standards and threats?

AssureSoft maintains alignment through continuous improvement processes, structured risk management, operational oversight, and ongoing governance by its Security Committee. This approach helps ensure security practices evolve alongside changing technologies, threats, and business requirements.

SECURITY PRACTICES

A structured security program built to protect what matters

Our security program protects customer data, supports business resilience, and promotes continuous improvement. It integrates governance, risk management, compliance, and data protection through unified practices based on internationally recognized security frameworks.

Security program

AssureSoft’s security program is built on its Information Security Management System (ISMS) to manage risk, protect information assets, and support compliance. It is continuously strengthened through initiatives including SOC 2 readiness. 

Governance & risk management

Risks are identified, evaluated, and treated through a structured, business-aligned process with clear ownership and accountability.

Operational security
 

Technical and administrative controls protect and monitor the systems and services used across our environment.

Incident management
 

Formal processes detect, escalate, and respond to security incidents, with post-incident analysis to strengthen resilience over time.

Vendor security
 

Third-party relationships are evaluated with security in mind, with contractual requirements and ongoing oversight where appropriate.

Security committee

AssureSoft operates a dedicated Security Committee that oversees the ISMS, assigns accountability, reviews security decisions, and drives continuous improvement. This body ensures security governance is part of a system that stays active and aligned with business priorities.    

Encryption standards

AssureSoft applies cryptographic controls to protect the confidentiality and integrity of sensitive information, both in transit and at rest. Encryption methods and key lifecycle management are owned by IT and Information Security.

Data protection

Encryption of sensitive data in transit and at rest.

Key management

Secure generation, storage, rotation and retirement of cryptographic keys.

Access control

Secure repositories with RBAC and audit logging.

Infrastructure

Approved cryptographic protocols for VPN and wireless.

Endpoints

Full disk encryption.

Secure communications

Authorized encrypted communication channels.

Data protection & access control

We apply controls to protect information throughout its entire lifecycle: from how it is accessed and classified to how it is securely retained and disposed of.

Access control

Access to systems is granted based on role, operational need, and prior authorization. Privileged access receives additional oversight and periodic review.

Information classification

Information is classified by sensitivity and handled in accordance with internal policies, ensuring appropriate protections at every stage.

Remote work & endpoints

Security expectations apply to remote work and corporate devices, protecting client and company information outside traditional office environments.

How does AssureSoft manage access when employees change roles or leave the company?

Access is managed through formal joiner, mover, and leaver processes. User permissions are assigned based on role, operational need, prior authorization, and least-privilege principles. Access rights are reviewed periodically, privileged access receives additional oversight, and accounts for separated personnel are disabled immediately.

What controls are in place for access to critical systems and source code?

Access to critical systems and source code is controlled through role-based permissions, operational need, prior authorization, and least-privilege principles. AssureSoft also provides additional oversight of privileged access, conducts periodic permission reviews, implements strong authentication controls, and enforces restrictions on remote and external access.

How does AssureSoft secure remote access and corporate devices?

Security expectations apply to remote work, corporate devices, and authorized access channels. AssureSoft protects client and company information through access restrictions, secure communication channels, encryption standards, endpoint controls, and defined usage policies for corporate systems and devices.

AI USE

We use AI thoughtfully and with clear guardrails

AssureSoft uses AI to support software development and internal processes, governed by a formal AI policy that prioritizes responsible use, data protection, and human accountability.

Governed use

Only approved AI tools may be used for company activities. New tools must go through a formal security, privacy, and business review before authorization.

Data protection

Confidential client data, credentials, architectures, and sensitive information may not be used in public or unapproved AI tools under any circumstances.

Human accountability

AI does not replace professional judgment. All outputs must be reviewed and validated by an accountable professional before use.

Intellectual property

Employees are responsible for ensuring AI-generated content does not introduce IP or licensing risks into client deliverables.

Can employees use public AI tools with customer-related work?

AssureSoft restricts the use of customer and sensitive information in public or unapproved AI tools. Confidential customer data, credentials, architectures, proprietary code, and other sensitive information may be used only in approved tools, under defined controls, and for authorized use cases.

How are new AI tools evaluated before they are approved internally?

New AI tools go through a formal evaluation process that considers security, privacy, data classification, and business justification before approval. Only authorized AI tools may be used for company activities.

Who is accountable for AI-generated code or content used in client work?

AI does not replace professional judgment at AssureSoft. All AI-generated outputs must be reviewed, validated, and approved by the responsible professional before use in client or internal work.

Still have security 
questions?

Our security team is happy to support your vendor 
evaluation and due diligence process.