Security & Compliance

Plain answers about where your data lives, who can reach it, and what happens if something goes wrong. If anything here is missing for your review process, email hello@assurio.app.

Data hosting

  • Customer data is stored in a managed PostgreSQL database hosted in the European Union (AWS eu-west-3, Paris).
  • All traffic between your browser and our servers is encrypted with TLS 1.2 or higher.
  • Data at rest — database storage, backups and uploaded files — is encrypted by the hosting provider.
  • Each customer's records are logically separated and enforced at the database level, not only in the application.

GDPR

  • For data you and your team enter into Assurio Hub and Assurio Stock Hero, Assurio acts as a data processor. You remain the data controller.
  • We support access, correction, export and deletion requests. Send them to hello@assurio.app and we respond within 30 days.
  • Sub-processors are limited to our hosting, email delivery and payment providers. We can share the current list on request.
  • Details of what we collect and why are in our Privacy Policy.

Access control

  • Access is role-based. Admins, managers and frontline staff see different actions and different data.
  • Permissions are set per site, so a team member at one property cannot see or edit another property's work orders or stock.
  • Account owners can add, change and remove access at any time; removal takes effect immediately.
  • Assurio staff access to production data is limited to the people who need it for support, and only when troubleshooting a reported issue.

Backups and recovery

  • The database is backed up automatically every day by our hosting provider.
  • Backups are encrypted and stored in the same EU region as the live database.
  • We can restore from the most recent daily backup on request. Contact us and we will confirm scope and timing before restoring anything.
  • Deleted accounts are removed from live systems immediately and age out of backups over time.

Compliance roadmap

  • Assurio is not currently SOC 2 certified. We do not present ourselves as compliant with standards we have not completed.
  • We are prepared to pursue a SOC 2 Type II audit when a customer or prospect requires it for their procurement process.
  • Once the audit is complete, we can share the SOC 2 report under a standard NDA as part of a signed agreement.
  • In the meantime, we are happy to answer security questionnaires, provide our DPA, and walk through our controls.

Status and capacity

  • Assurio runs on managed EU cloud infrastructure. Database compute, storage and connection capacity are scaled up as customer numbers grow, without downtime for day-to-day increases.
  • We monitor database load, storage use, slow queries and error rates, and act on warning signs before they affect the people using the apps.
  • A live service check is available at assurio.app/health, which confirms the site and its backend are responding.
  • Assurio Hub and Assurio Stock Hero run as separate services, so heavy use of one does not slow the other.
  • If we ever have planned maintenance that could interrupt service, we will tell affected customers by email in advance.

Our commitment

  • Assurio is not SOC 2 or ISO 27001 certified. We do not claim certifications we do not hold, and we will say so plainly in any procurement questionnaire.
  • We review our security practices as the platform grows — access reviews, dependency updates, and tightening database rules are ongoing work, not a one-off project.
  • If you find a security issue, email hello@assurio.app and we will acknowledge it within two working days.

Need a Data Processing Agreement?

We provide a standard DPA, including EU standard contractual clauses where relevant, for customers who need one on file. Tell us your legal entity name and the products you use, and we will send a copy to sign.

See also our Privacy Policy and Terms of Service.