Assay
Product
Truth GraphOne verified source for everything you sell Collateral EngineProposals and battlecards that are always right Readiness EngineKnow what your team knows, continuously
Pricing Request Early Access

Legal

Security

Last updated · May 22, 2026 Version · 3.0 Applies to · assay.wiki, app.assay.wiki, assay.wiki
The short version: TLS 1.3 in transit, AES-256 at rest, SSO and SCIM, no customer content in training, annual third-party pen test, and a one-hour customer notification SLA for any incident. Findings disclose at security@assay.wiki.
On this page
  1. 01Trust model
  2. 02Encryption
  3. 03Access control
  4. 04Tenant isolation
  5. 05AI safety
  6. 06Vulnerability mgmt
  7. 07Incident response
  8. 08Audits + certifications
  9. 09Business continuity
  10. 10Responsible disclosure
  11. 11Contact

01Trust model

Default deny. Customer-isolated by design. No customer-data-in-training, ever.

Assay was architected against three assumptions: (a) customer commercial knowledge is sensitive enough that breach is unacceptable; (b) foundation-model providers are part of the trust boundary and must be contractually constrained; (c) the EU AI Act and equivalent frameworks will treat audit logs as evidentiary records. Our controls are designed to satisfy all three.

02Encryption

TLS 1.3 in transit. AES-256 at rest. Customer-isolated keys with 90-day rotation.

All network traffic — client to platform, service to service, and platform to sub-processors — uses TLS 1.3 with modern cipher suites only. HSTS is preloaded on all customer-facing domains. Data at rest is encrypted with AES-256 using tenant-scoped envelope encryption. Data-encryption keys are rotated every 90 days. Enterprise customers can bring their own keys via AWS KMS or GCP CMEK; we surrender access to encrypted material if a customer revokes their key.

03Access control

SSO and SCIM on every paid tier. Role separation enforced at the system level.

SAML 2.0 and OpenID Connect SSO are available on every paid tier; SCIM 2.0 provisioning is standard on Enterprise. Role-based access control inside Assay maps directly to the EU AI Act Article 14 segregation-of-duties model: authoring, approval, and publishing of any commercial claim are separate roles enforced at the application layer. Assay employees access customer environments only with documented just-in-time approval; all access is logged and reviewed monthly.

04Tenant isolation

Logical separation everywhere. Physical separation available on Enterprise.

The standard architecture provides logical tenant isolation: each customer's Truth Graph, content, and inference logs are scoped to a tenant ID enforced at every layer of the application and database, with row-level security and per-tenant encryption keys. Enterprise customers can elect single-tenant deployments with dedicated compute and storage in either US or EU regions.

05AI safety

No customer content in training. Prompts and outputs retained for audit, not for model improvement.

No customer content — including prompts, retrieved sources, generated outputs, or Truth Graph nodes — is used to train, fine-tune, or evaluate foundation models, ours or our sub-processors'. This is contractually enforced with every model provider in our supply chain and verified annually. We retain prompts and outputs for audit purposes per EU AI Act Article 19; that retention is fully separable from any model-training pathway.

06Vulnerability management

SAST + DAST on every PR. Dependency scanning on every build. Annual third-party pen test.

Every pull request runs static and dynamic application-security scans before merge. Dependencies are scanned continuously; high-severity findings block deployment. We engage an independent security firm to conduct a black-box penetration test annually; findings are remediated against a published SLA (critical: 7 days, high: 30 days, medium: 90 days) and the executive summary is available to customers under NDA.

07Incident response

Customer notification within one hour of confirmation. Post-mortem within five business days.

If we confirm an incident affecting customer data or service availability, we notify the affected customer's primary security contact within one hour, with a status update at least every four hours until resolution. A written post-mortem — including root cause, scope, customer impact, and remediation steps — is published to the affected customer and to our Trust page within five business days. We do not delay disclosure to investigate reputational consequences.

08Audits + certifications

SOC 2 Type I (complete). SOC 2 Type II (in progress). ISO 27001 (scoped for 2027).

SOC 2 Type I was completed in January 2026 by an independent firm. SOC 2 Type II is in audit observation through September 2026; we expect to publish the report in October 2026. ISO 27001 is scoped for 2027. HIPAA-eligible deployment is available to Enterprise customers under a BAA. Reports and BAAs are available under NDA from security@assay.wiki.

09Business continuity

Multi-region backups. RPO 1 hour. RTO 4 hours.

Customer data is backed up continuously to a second region in the same jurisdiction (US backups in a second US region; EU backups in a second EU region). Our recovery point objective is one hour and our recovery time objective is four hours. Disaster recovery exercises are conducted twice annually; results are reported to customers on request.

10Responsible disclosure

Report issues to security@assay.wiki. We respond within 24 hours and credit researchers who follow the policy.

If you discover a security issue, please email security@assay.wiki with reproduction steps. Do not exploit the issue beyond what is necessary to demonstrate it, and do not access data that is not yours. We acknowledge reports within 24 hours, resolve confirmed issues against the SLAs in section 06, and publicly credit researchers (with their permission) in our annual security report. We do not pursue legal action against good-faith researchers who follow this policy.

11Contact

Reach the right person directly:

Security disclosure
security@assay.wiki
Audit reports + BAA
trust@assay.wiki
Founder · escalation
kaustubh@assay.wiki
Assay

Every claim, verified.

Product
  • Truth Graph
  • Collateral Engine
  • Readiness Engine
  • Pricing
Company
  • About
  • Blog
  • Early Access
Legal
  • Privacy
  • Terms
  • Security
  • Trust
© 2026 Assay · The Commercial Truth Platform
LinkedInX / Twitter

Analytics notice

We measure how visitors use this site — pages viewed, clicks, and flow — to improve the product. See our Cookie Policy and Privacy Policy.