Security controls
Secure HTTP-only auth cookies, role-based policies, tenant isolation, API-key hashing and rotation, SQL parameterization, rate limiting, resilient outbound calls, audit logs, and admin security review pages.
Security PracticesTrust center
Buyer-facing overview of the controls and operating boundaries currently implemented in AssetLed: security, privacy, availability, subprocessors, abuse handling, and disclosure routes.
Secure HTTP-only auth cookies, role-based policies, tenant isolation, API-key hashing and rotation, SQL parameterization, rate limiting, resilient outbound calls, audit logs, and admin security review pages.
Security PracticesCompliance export, deletion workflows, public privacy request and deletion pages, retention settings, legal holds, suppression records, Google OAuth minimization, and product email consent controls.
Privacy requestPublic status, internal health checks, Hangfire job monitoring, operational logs, integration status review, and admin job controls for background processing.
System statusTrial-abuse prevention, payment-abuse signals, suppressions, unsubscribe enforcement, mailbox guardrails, rate limiting, security alerts, and abuse contact routing.
Abuse contactPublic subprocessor categories cover hosting, SQL Server, Mailgun product email, outreach mailbox providers, Stripe, Google, AI providers, DataForSEO, logging, source control, and CI.
SubprocessorsResponsible disclosure uses the security contact route with testing boundaries that prohibit destructive testing, spam, credential stuffing, social engineering, and access to another customer's data.
Security contactUse these public documents for procurement, privacy review, and security review. The pages describe implemented controls only and do not claim certifications that are not present in the product.