OUR COMMITMENT TO PROTECTING YOUR DATA
Trust Center
Security, transparency, and accountability
Everything you need to learn about AssureSoft’s approach to information security and data protection.
CERTIFICATIONS
Backed by internationally recognized standards
Our certifications provide independent validation that our security practices meet rigorous global benchmarks.
ISO/IEC 27001:2022
Active
AssureSoft is certified to ISO/IEC 27001:2022 by TÜV Rheinland of North America. This certification covers software development, quality control, project management, and IT service support.
SOC 2 Type II
In Progress
AssureSoft is currently undergoing a SOC 2 Type II audit to assess the effectiveness of our security and confidentiality controls over time.
How does AssureSoft review and improve its security controls?
AssureSoft reviews and improves its security controls through ongoing risk management, compliance activities, incident analysis, and continuous improvement processes aligned with its ISO/IEC 27001:2022-certified Information Security Management System. This includes governance, operational security, data protection, vendor security, and incident response practices.
What does ISO/IEC 27001 certification mean in practice for software partnerships?
ISO/IEC 27001 certification provides independent validation that AssureSoft operates under a structured Information Security Management System covering governance, operational security, risk management, incident response, and continuous improvement practices.
How does AssureSoft maintain alignment with evolving security standards and threats?
AssureSoft maintains alignment through continuous improvement processes, structured risk management, operational oversight, and ongoing governance by its Security Committee. This approach helps ensure security practices evolve alongside changing technologies, threats, and business requirements.
SECURITY PRACTICES
A structured security program built to protect what matters
Our security program protects customer data, supports business resilience, and promotes continuous improvement. It integrates governance, risk management, compliance, and data protection through unified practices based on internationally recognized security frameworks.
Security program
AssureSoft’s security program is built on its Information Security Management System (ISMS) to manage risk, protect information assets, and support compliance. It is continuously strengthened through initiatives including SOC 2 readiness.
Governance & risk management
Risks are identified, evaluated, and treated through a structured, business-aligned process with clear ownership and accountability.
Operational security
Technical and administrative controls protect and monitor the systems and services used across our environment.
Incident management
Formal processes detect, escalate, and respond to security incidents, with post-incident analysis to strengthen resilience over time.
Vendor security
Third-party relationships are evaluated with security in mind, with contractual requirements and ongoing oversight where appropriate.
Security committee
AssureSoft operates a dedicated Security Committee that oversees the ISMS, assigns accountability, reviews security decisions, and drives continuous improvement. This body ensures security governance is part of a system that stays active and aligned with business priorities.
Encryption standards
AssureSoft applies cryptographic controls to protect the confidentiality and integrity of sensitive information, both in transit and at rest. Encryption methods and key lifecycle management are owned by IT and Information Security.
Data protection
Encryption of sensitive data in transit and at rest.
Key management
Secure generation, storage, rotation and retirement of cryptographic keys.
Access control
Secure repositories with RBAC and audit logging.
Infrastructure
Approved cryptographic protocols for VPN and wireless.
Endpoints
Full disk encryption.
Secure communications
Authorized encrypted communication channels.
Data protection & access control
We apply controls to protect information throughout its entire lifecycle: from how it is accessed and classified to how it is securely retained and disposed of.
Access control
Access to systems is granted based on role, operational need, and prior authorization. Privileged access receives additional oversight and periodic review.
Information classification
Information is classified by sensitivity and handled in accordance with internal policies, ensuring appropriate protections at every stage.
Remote work & endpoints
Security expectations apply to remote work and corporate devices, protecting client and company information outside traditional office environments.
How does AssureSoft manage access when employees change roles or leave the company?
Access is managed through formal joiner, mover, and leaver processes. User permissions are assigned based on role, operational need, prior authorization, and least-privilege principles. Access rights are reviewed periodically, privileged access receives additional oversight, and accounts for separated personnel are disabled immediately.
What controls are in place for access to critical systems and source code?
Access to critical systems and source code is controlled through role-based permissions, operational need, prior authorization, and least-privilege principles. AssureSoft also provides additional oversight of privileged access, conducts periodic permission reviews, implements strong authentication controls, and enforces restrictions on remote and external access.
How does AssureSoft secure remote access and corporate devices?
Security expectations apply to remote work, corporate devices, and authorized access channels. AssureSoft protects client and company information through access restrictions, secure communication channels, encryption standards, endpoint controls, and defined usage policies for corporate systems and devices.
AI USE
We use AI thoughtfully and with clear guardrails
AssureSoft uses AI to support software development and internal processes, governed by a formal AI policy that prioritizes responsible use, data protection, and human accountability.
Governed use
Only approved AI tools may be used for company activities. New tools must go through a formal security, privacy, and business review before authorization.
Data protection
Confidential client data, credentials, architectures, and sensitive information may not be used in public or unapproved AI tools under any circumstances.
Human accountability
AI does not replace professional judgment. All outputs must be reviewed and validated by an accountable professional before use.
Intellectual property
Employees are responsible for ensuring AI-generated content does not introduce IP or licensing risks into client deliverables.
Can employees use public AI tools with customer-related work?
AssureSoft restricts the use of customer and sensitive information in public or unapproved AI tools. Confidential customer data, credentials, architectures, proprietary code, and other sensitive information may be used only in approved tools, under defined controls, and for authorized use cases.
How are new AI tools evaluated before they are approved internally?
New AI tools go through a formal evaluation process that considers security, privacy, data classification, and business justification before approval. Only authorized AI tools may be used for company activities.
Who is accountable for AI-generated code or content used in client work?
AI does not replace professional judgment at AssureSoft. All AI-generated outputs must be reviewed, validated, and approved by the responsible professional before use in client or internal work.