AssetSort

SEC · Security & Privacy

How AssetSort handles your data

Isolation, encryption, and backups.

4 min read

Every organisation's data is isolated by the API's authorization layer: every request is checked against your live membership and, for MSP staff, your live client scope, before any data is read or written. That scope is re-derived on each request rather than baked into a session, so revoking someone's access to a client takes effect immediately — including on any calendar feed they'd subscribed to. The isolation rules are covered by an automated test suite rather than resting on policy alone. All data is encrypted in transit and at rest, and Microsoft 365 credentials live in Google Secret Manager, never in the application database. If you unlink a managed client, it becomes standalone again instantly — its data stays intact and your staff's access is revoked at that moment. For current backup and retention commitments, ask us via the contact details in "How to reach support" — we'd rather give you the live figure than an out-of-date one here.