Resources · Security

Security built for
financial data.

Trust accounting, owner financials, and tenant records require enterprise-grade security. Here's exactly how AssetView protects your data.

Security architecture

Every layer protected

🔒

Encryption at Rest

All data encrypted with AES-256. PostgreSQL databases, document storage, and backups — all encrypted before they touch disk.

🛡️

TLS 1.3 in Transit

All data transmitted between your browser and our servers uses TLS 1.3. No unencrypted connections accepted.

👥

Role-Based Access Control

Six user roles — admin, manager, owner, auditor, vendor, tenant — each with precisely scoped permissions enforced at every API endpoint.

🏢

Multi-Tenant Isolation

Every query is scoped by company ID. Cross-tenant data access is architecturally impossible — not just policy-blocked.

📋

Complete Audit Logging

Every action — logins, data changes, exports, approvals — is logged with timestamp, user, IP address, and entity reference. Logs are immutable.

🔐

MFA Enforcement

Multi-factor authentication available for all users, required for admin and auditor roles. TOTP-based with recovery codes.

🌐

IP Allowlisting

Auditor accounts support IP allowlisting — access is only permitted from pre-approved IP ranges.

💾

Daily Backups

Automated daily backups with 30-day retention. Point-in-time recovery available. RTO: 4 hours. RPO: 1 hour.

🔑

SHA-256 Chain of Custody

Every financial transaction and document upload generates a SHA-256 hashed receipt — permanent, non-modifiable, and verifiable independently.

Questions about security?

Contact our team for a detailed security review or to request our security documentation.