Assura processes sensitive compliance data on behalf of organisations across the Caribbean. We take the security of that data seriously — applying the same standards of protection that we help our clients achieve. This page describes the technical and organisational measures we have in place.
The Assura platform is deployed on Amazon Web Services, one of the world’s most widely used and audited cloud infrastructure providers. AWS maintains certifications including ISO 27001, SOC 1/2/3, and PCI DSS. Our deployment uses a high-availability architecture with automated failover to minimise downtime.
All platform data is stored in MongoDB Atlas, a fully managed cloud database service with built-in security controls.
All traffic to the Assura platform and website is routed through Cloudflare’s global network.
| Data state | Standard | Detail |
|---|---|---|
| Data at rest | AES-256 | Applied at database and storage layer via MongoDB Atlas |
| Data in transit | TLS 1.3 | All connections between browser and platform, enforced via Cloudflare. TLS 1.0 and 1.1 disabled |
| Passwords | Bcrypt | User passwords are hashed with bcrypt before storage. Plain text passwords are never stored or logged |
| Backups | AES-256 | Backup snapshots are encrypted using the same standard as live data |
We maintain an internal incident response procedure covering detection, containment, investigation, notification, and post-incident review. In the event of a personal data breach affecting your organisation’s data, we will notify you without undue delay and in accordance with our obligations as your data processor under applicable Caribbean data protection law — enabling you to meet your own regulatory notification obligations.
Assura is built by a team of data protection professionals. Privacy considerations are embedded in every feature development decision — not added as an afterthought. Data minimisation, purpose limitation, and access restriction are applied as default design principles throughout the platform.
We process only the personal data necessary to provide the platform and do not use client compliance data for any secondary purpose including marketing, profiling, or analytics beyond platform improvement.
A Data Processing Agreement (DPA) is available to all Assura subscribers, governing our obligations as your data processor. The DPA is available at getassura.app/dpa.html. Enterprise clients may request a customised DPA as part of their engagement.
Additional security documentation — including our information security policy summary, sub-processor list, and infrastructure security overview — is available on request to subscribers and prospective Enterprise clients.
If you discover a potential security vulnerability in the Assura platform, we ask that you report it to us responsibly before any public disclosure, giving us reasonable time to investigate and remediate. Please contact us at [email protected] with a description of the issue. We do not operate a formal bug bounty programme at this time but we take all responsible disclosures seriously and will acknowledge your report promptly.
For security-related questions, to request documentation, or to report a vulnerability, contact us at [email protected]. For Enterprise clients, your account contact is the first point of call.