Back to sign inAsaterra, LLC
Effective Date: January 1, 2026Asaterra, LLC recognizes the importance of protecting the confidentiality, integrity, and availability of customer information and the systems used to provide the Asaterra website, software platform, applications, portals, dashboards, mobile interfaces, integrations, and related services, collectively referred to as the “Services.”
This Security Notice provides a general description of Asaterra’s approach to information security. It is intended for informational purposes and does not replace or modify the security, confidentiality, privacy, service-level, or data-processing obligations contained in an executed customer agreement.
Asaterra maintains a risk-based information-security program designed to protect the Services and information processed through them.
The security program is intended to address areas including:
Security controls may vary depending on the nature of the Service, the type and sensitivity of the information, the customer’s configuration, applicable contractual requirements, and the systems or third-party services involved.
Security is a shared responsibility among Asaterra, its customers, authorized users, hosting and technology providers, equipment providers, integration partners, and other parties involved in providing or using the Services.
Asaterra is responsible for implementing and maintaining security measures within the systems and environments under its control.
Customers are responsible for matters under their control, including:
Security protections may be reduced when a customer or user improperly configures the Services, shares credentials, disables available security features, connects an insecure third-party system, or fails to follow reasonable security practices.
Access to the Asaterra Platform is limited to authorized users and personnel with an appropriate business need.
Depending on the applicable system and customer configuration, security measures may include:
Customers are responsible for assigning permissions that are appropriate for each user’s responsibilities.
Users must not share passwords, authentication codes, access tokens, or other credentials with unauthorized individuals.
Asaterra uses authentication controls designed to reduce unauthorized access to the Services.
Passwords may be protected through secure hashing, encryption, or approved identity and authentication services. Asaterra does not intend to store passwords in readable plain-text form.
Multifactor authentication is available and may be required based on user role, customer configuration, or security needs.
Asaterra may require users to:
Customers should use single sign-on, multifactor authentication, or other enhanced authentication features when available and appropriate for their organization.
Asaterra uses technical and organizational measures designed to protect information during transmission and processing.
These measures may include:
Certain information may be decrypted or otherwise made readable when it is actively processed, displayed to an authorized user, transmitted to an authorized integration, or used to provide the Services.
Customers are responsible for using secure methods when downloading, exporting, transmitting, or storing information outside the Asaterra-controlled environment.
The Asaterra Platform is hosted using Amazon Web Services (AWS) cloud infrastructure. Asaterra may also use established third-party providers for authentication, communications, monitoring, data storage, software development, customer support, and related technology services.
Asaterra selects and manages providers based on factors that may include:
AWS and other third-party infrastructure providers remain responsible for the security of the systems and services under their control. Asaterra remains responsible for configuring and using those services in accordance with its contractual obligations and reasonable security practices.
The use of AWS does not create a direct contractual relationship between the customer and AWS unless the customer separately contracts with AWS.
Asaterra uses logical access restrictions intended to prevent one customer from accessing another customer’s information without authorization.
Customer access may be separated through controls including:
No customer or user may attempt to access another customer’s environment, information, accounts, integrations, or records without express authorization.
Customer-owned hosting environments, dedicated deployments, or customer-specific configurations may be governed by additional security terms in the applicable customer agreement.
Asaterra incorporates security considerations into the design, development, testing, deployment, and maintenance of the Services.
Security practices may include:
The timing and priority of remediation may depend on the severity of the issue, likelihood of exploitation, potential impact, availability of a reliable correction, and the risks associated with implementing the correction.
Asaterra maintains processes intended to identify, evaluate, prioritize, and address security vulnerabilities affecting systems under its control.
These processes may include:
Not every available update or patch can be installed immediately. Asaterra may evaluate compatibility, operational impact, severity, exploitability, and other risks before deploying an update.
When immediate remediation is not reasonably available, Asaterra may use compensating controls or other risk-reduction measures where appropriate.
Asaterra may collect and review system, application, authentication, administrative, audit, integration, and security logs to:
Logging capabilities and retention periods may vary by system, customer configuration, contractual requirement, and operational need.
Asaterra does not guarantee that every unauthorized action, error, attack, or security event will be identified immediately or prevented.
Access by Asaterra personnel and authorized contractors is limited according to business responsibilities and operational needs.
Security measures may include:
Access to customer information may be provided when reasonably necessary to support, secure, troubleshoot, maintain, or improve the Services or to comply with an authorized customer request or legal obligation.
Asaterra may use third-party providers to support cloud hosting, software development, authentication, monitoring, communications, document storage, customer support, billing, data processing, and other business functions.
Asaterra evaluates service providers according to the nature of the service and the information they may process.
As appropriate, Asaterra may use measures including:
Third-party services are not entirely controlled by Asaterra. A third-party failure, vulnerability, interruption, or security event may affect the availability or security of the Services.
Asaterra maintains backup and recovery processes designed to support the restoration of systems and information following certain failures, disruptions, or security events.
Depending on the applicable Service, these processes may include:
Backup frequency, recovery capabilities, recovery time, and data-retention periods may vary by system and customer agreement.
Backups are not a substitute for customer-controlled recordkeeping. Customers should maintain independent copies of information when required by law, regulation, customer policy, or operational need.
Unless expressly provided in an applicable customer agreement, Asaterra does not guarantee that all information can be restored without any loss following every type of interruption or event.
Asaterra maintains procedures intended to identify, evaluate, contain, investigate, remediate, and recover from suspected or confirmed security incidents.
Incident-response activities may include:
Asaterra will provide customer notification of a confirmed security incident affecting customer information when required by applicable law or an applicable customer agreement.
The timing and content of a notification may depend on the nature of the incident, the availability of reliable information, law-enforcement requests, containment efforts, legal requirements, and the applicable customer agreement.
Customers and authorized users must take reasonable measures to protect their access to the Services.
Customers and users should:
Users should not enter highly sensitive personal information, regulated information, payment-card information, medical information, government identification numbers, authentication secrets, or other restricted information into the Platform unless the applicable customer agreement and Platform configuration expressly permit that information.
Customers may choose to connect the Services to third-party software, equipment, sensors, databases, identity providers, communication services, or other systems.
The security of an integration depends on multiple parties, including Asaterra, the customer, the integration provider, the equipment provider, and the network or systems through which data is transmitted.
Customers are responsible for:
Asaterra is not responsible for security vulnerabilities or unauthorized access originating within a customer-controlled or third-party system except to the extent expressly stated in an applicable written agreement.
Asaterra may perform or arrange for security reviews, vulnerability assessments, code analysis, configuration reviews, penetration testing, or other evaluations based on the maturity, scope, and risk profile of the applicable Services.
Any security certification, independent audit, penetration-test result, compliance report, or formal assurance held by Asaterra will be identified only through authorized documentation.
This Security Notice does not represent that Asaterra holds a specific certification, audit report, or regulatory designation unless that certification or designation is expressly stated in writing by Asaterra.
Security reports and detailed technical documentation may contain confidential information and may be provided only to qualified customers under appropriate confidentiality protections.
Customers, users, and security researchers should promptly report suspected vulnerabilities, unauthorized access, compromised credentials, or other security concerns.
Reports should include, when available:
Security reports should not include unnecessary customer data, personal information, passwords, access tokens, or other sensitive information.
Reports may be submitted to:
Security Email: security@asaterra.com
A report does not authorize an individual to access data, disrupt systems, conduct testing, exploit a vulnerability, or violate the Terms of Use.
No individual or organization may perform vulnerability scanning, penetration testing, automated testing, denial-of-service testing, social engineering, credential testing, data extraction, or other security testing against the Services without Asaterra’s prior written authorization.
Authorized testing must remain within the approved scope and must not:
Asaterra may suspend or restrict access when it reasonably believes that unauthorized testing or harmful activity is occurring.
Asaterra uses safeguards designed to reduce security risks, but no technology, network, software platform, cloud environment, transmission method, or security program is completely secure.
Asaterra cannot guarantee that:
Customers should evaluate the Services in light of their own security, legal, regulatory, contractual, and operational requirements.
This Security Notice provides a general overview and does not create a separate warranty, service-level commitment, certification, indemnification obligation, or contractual guarantee.
Specific security requirements applicable to a customer may be contained in:
If this Security Notice conflicts with an executed agreement between Asaterra and a customer, the executed agreement will control to the extent of the conflict.
Asaterra may update this Security Notice periodically to reflect changes to:
The revised Security Notice will be posted with an updated effective date.
Material changes will be communicated when required by applicable law or an executed customer agreement.
Asaterra, LLC operates as a virtual company and does not maintain a public customer-facing office.
Questions or concerns regarding this Security Notice may be directed to:
Security Email: security@asaterra.com
Privacy Email: privacy@asaterra.com
Legal Email: legal@asaterra.com
Website: asaterra.com
Formal notices must be provided in accordance with the applicable customer agreement.
--END OF SECURITY NOTICE--