Welcome to Assurentry! New FDA compliance features available.
Skip to main content
Security & compliance

Trust Center

Your FDA compliance data deserves enterprise-grade protection. Learn about the security practices, certifications, and infrastructure that keep your information safe.

How Does Assurentry Protect Your Data?

Assurentry employs a defense-in-depth security strategy to protect your FDA compliance data. All information is encrypted with AES-256 encryption at rest and TLS 1.3 in transit. Our platform is hosted on SOC 2 Type II–certified cloud infrastructure, inheriting the independent audit controls of our hosting providers. Access is governed by role-based controls with mandatory multi-factor authentication. All data resides in US-based data centers with physical and logical security controls, and our dedicated security team provides 24/7 monitoring across the entire infrastructure.

Security by the Numbers

Measurable commitments that demonstrate our dedication to protecting your data.

TLS 1.3
Encrypted in Transit
256-bit
AES Encryption
24/7
Security Monitoring
MFA
Enforced for Staff

Security Measures

How we protect your data and maintain the highest security standards across every layer of the platform.

Data Encryption

AES-256 encryption protects all data at rest. TLS 1.3 secures every byte in transit between your browser and our servers, ensuring end-to-end confidentiality.

Network Protection

Traffic is served over hardened, isolated infrastructure with TLS-only connections and provider-managed firewall and DDoS protections at the edge.

Access Controls

Role-based access controls (RBAC) restrict data to authorized personnel only. Multi-factor authentication is enforced for all staff and admin accounts.

Data Residency

All customer data is stored exclusively in US-based data centers with strict physical security, biometric access, and 24/7 surveillance.

Key Management

Encryption keys are managed through HSM-backed systems with automated key rotation policies, ensuring keys are never exposed in plaintext.

Audit Logging

Every user action, API call, and administrative change is recorded in immutable audit logs, providing a complete trail for compliance reviews.

Security & Compliance Posture

The infrastructure certifications we build on and the regulatory frameworks our platform is designed to align with.

AES-256 Encryption

All data protected with AES-256 encryption at rest and TLS 1.3 in transit, ensuring end-to-end confidentiality across the platform.

Certified Infrastructure

Our platform is hosted on SOC 2 Type II–certified cloud infrastructure, inheriting the physical and operational security controls of our hosting providers.

Role-Based Access

Access to customer data is restricted to authorized personnel through role-based access controls, with multi-factor authentication enforced for all staff accounts.

FDA 21 CFR Part 11

Our platform is designed with awareness of FDA 21 CFR Part 11 requirements for electronic records, electronic signatures, and audit trails.

Privacy-Conscious Data Handling

We follow data-minimization and purpose-limitation practices and support data subject requests such as access, correction, and deletion. See our Privacy Policy for details.

Audit Logging

User actions, API calls, and administrative changes are recorded in audit logs, providing a trail for internal compliance reviews.

Infrastructure & Reliability

Built for reliability with redundant systems and a dedicated incident response team.

High-Availability Hosting

Our online portal and client-facing tools run on high-availability cloud infrastructure designed with redundant systems and automated failover across multiple availability zones.

  • Multi-zone redundant architecture
  • Automated failover and self-healing systems
  • Real-time health monitoring and alerting
  • Scheduled maintenance windows communicated in advance

Incident Response

Our dedicated security team monitors systems around the clock with a 24-hour incident response commitment for any security events. Every incident follows a structured response process with clear escalation procedures.

  • 24/7 automated threat detection and monitoring
  • Documented escalation procedures to senior leadership
  • Affected client notification within 24 hours
  • Comprehensive post-incident reporting and remediation

Frequently Asked Questions

Common questions about our security practices, data handling, and compliance certifications.

Security questions?

Contact our security team for detailed information about our practices.

AES-256 encryption · Built on cloud infrastructure that maintains SOC 2 Type II certification