Trust accounting, owner financials, and tenant records require enterprise-grade security. Here's exactly how AssetView protects your data.
All data encrypted with AES-256. PostgreSQL databases, document storage, and backups — all encrypted before they touch disk.
All data transmitted between your browser and our servers uses TLS 1.3. No unencrypted connections accepted.
Six user roles — admin, manager, owner, auditor, vendor, tenant — each with precisely scoped permissions enforced at every API endpoint.
Every query is scoped by company ID. Cross-tenant data access is architecturally impossible — not just policy-blocked.
Every action — logins, data changes, exports, approvals — is logged with timestamp, user, IP address, and entity reference. Logs are immutable.
Multi-factor authentication available for all users, required for admin and auditor roles. TOTP-based with recovery codes.
Auditor accounts support IP allowlisting — access is only permitted from pre-approved IP ranges.
Automated daily backups with 30-day retention. Point-in-time recovery available. RTO: 4 hours. RPO: 1 hour.
Every financial transaction and document upload generates a SHA-256 hashed receipt — permanent, non-modifiable, and verifiable independently.
Contact our team for a detailed security review or to request our security documentation.