Security

Security at Assura

Last updated: 23 May 2026

Assura processes sensitive compliance data on behalf of organisations across the Caribbean. We take the security of that data seriously — applying the same standards of protection that we help our clients achieve. This page describes the technical and organisational measures we have in place.

Infrastructure

Cloud hosting — Amazon Web Services (AWS)

The Assura platform is deployed on Amazon Web Services, one of the world’s most widely used and audited cloud infrastructure providers. AWS maintains certifications including ISO 27001, SOC 1/2/3, and PCI DSS. Our deployment uses a high-availability architecture with automated failover to minimise downtime.

Database — MongoDB Atlas

All platform data is stored in MongoDB Atlas, a fully managed cloud database service with built-in security controls.

Network — Cloudflare

All traffic to the Assura platform and website is routed through Cloudflare’s global network.

Data Encryption

Data stateStandardDetail
Data at restAES-256Applied at database and storage layer via MongoDB Atlas
Data in transitTLS 1.3All connections between browser and platform, enforced via Cloudflare. TLS 1.0 and 1.1 disabled
PasswordsBcryptUser passwords are hashed with bcrypt before storage. Plain text passwords are never stored or logged
BackupsAES-256Backup snapshots are encrypted using the same standard as live data

Access Controls

Within the platform

Internal access (Assura staff)

Application Security

Incident Response

We maintain an internal incident response procedure covering detection, containment, investigation, notification, and post-incident review. In the event of a personal data breach affecting your organisation’s data, we will notify you without undue delay and in accordance with our obligations as your data processor under applicable Caribbean data protection law — enabling you to meet your own regulatory notification obligations.

Business Continuity

Privacy by Design

Assura is built by a team of data protection professionals. Privacy considerations are embedded in every feature development decision — not added as an afterthought. Data minimisation, purpose limitation, and access restriction are applied as default design principles throughout the platform.

We process only the personal data necessary to provide the platform and do not use client compliance data for any secondary purpose including marketing, profiling, or analytics beyond platform improvement.

Data Processing Agreement

A Data Processing Agreement (DPA) is available to all Assura subscribers, governing our obligations as your data processor. The DPA is available at getassura.app/dpa.html. Enterprise clients may request a customised DPA as part of their engagement.

Security Documentation

Additional security documentation — including our information security policy summary, sub-processor list, and infrastructure security overview — is available on request to subscribers and prospective Enterprise clients.

Responsible Disclosure

If you discover a potential security vulnerability in the Assura platform, we ask that you report it to us responsibly before any public disclosure, giving us reasonable time to investigate and remediate. Please contact us at [email protected] with a description of the issue. We do not operate a formal bug bounty programme at this time but we take all responsible disclosures seriously and will acknowledge your report promptly.

Security enquiries

For security-related questions, to request documentation, or to report a vulnerability, contact us at [email protected]. For Enterprise clients, your account contact is the first point of call.