AsaterraBack to sign in

Security Notice

Asaterra, LLC

Effective Date: January 1, 2026

Asaterra, LLC recognizes the importance of protecting the confidentiality, integrity, and availability of customer information and the systems used to provide the Asaterra website, software platform, applications, portals, dashboards, mobile interfaces, integrations, and related services, collectively referred to as the “Services.”

This Security Notice provides a general description of Asaterra’s approach to information security. It is intended for informational purposes and does not replace or modify the security, confidentiality, privacy, service-level, or data-processing obligations contained in an executed customer agreement.

1. Security Program

Asaterra maintains a risk-based information-security program designed to protect the Services and information processed through them.

The security program is intended to address areas including:

  • Security governance and accountability;
  • Identification and assessment of security risks;
  • Access management and authentication;
  • Data protection;
  • Secure software development;
  • Infrastructure and application monitoring;
  • Vulnerability and patch management;
  • Incident detection and response;
  • Business continuity and recovery;
  • Service-provider oversight; and
  • Periodic evaluation and improvement of security practices.

Security controls may vary depending on the nature of the Service, the type and sensitivity of the information, the customer’s configuration, applicable contractual requirements, and the systems or third-party services involved.

2. Shared Security Responsibility

Security is a shared responsibility among Asaterra, its customers, authorized users, hosting and technology providers, equipment providers, integration partners, and other parties involved in providing or using the Services.

Asaterra is responsible for implementing and maintaining security measures within the systems and environments under its control.

Customers are responsible for matters under their control, including:

  • Determining who should have access to the Services;
  • Assigning appropriate user roles and permissions;
  • Promptly disabling accounts that are no longer required;
  • Protecting customer-managed systems, devices, networks, and credentials;
  • Configuring integrations and notifications appropriately;
  • Reviewing user activity and access where appropriate;
  • Maintaining accurate account and contact information;
  • Training authorized users;
  • Complying with applicable privacy, security, and records-management requirements; and
  • Promptly reporting suspected unauthorized access or security concerns.

Security protections may be reduced when a customer or user improperly configures the Services, shares credentials, disables available security features, connects an insecure third-party system, or fails to follow reasonable security practices.

3. Access Controls

Access to the Asaterra Platform is limited to authorized users and personnel with an appropriate business need.

Depending on the applicable system and customer configuration, security measures may include:

  • Unique user accounts;
  • Role-based access controls;
  • Permission-based access to organizations, facilities, records, and Platform functions;
  • Password requirements;
  • Multifactor authentication;
  • Session controls;
  • Account-lockout or rate-limiting controls;
  • Administrative approval processes;
  • Periodic access review; and
  • Logging of authentication and administrative activity.

Customers are responsible for assigning permissions that are appropriate for each user’s responsibilities.

Users must not share passwords, authentication codes, access tokens, or other credentials with unauthorized individuals.

4. Authentication and Password Security

Asaterra uses authentication controls designed to reduce unauthorized access to the Services.

Passwords may be protected through secure hashing, encryption, or approved identity and authentication services. Asaterra does not intend to store passwords in readable plain-text form.

Multifactor authentication is available and may be required based on user role, customer configuration, or security needs.

Asaterra may require users to:

  • Create passwords that satisfy established complexity requirements;
  • Use multifactor authentication;
  • Reauthenticate after a period of inactivity;
  • Reset a password following suspected compromise; or
  • Complete additional identity-verification steps.

Customers should use single sign-on, multifactor authentication, or other enhanced authentication features when available and appropriate for their organization.

5. Data Protection and Encryption

Asaterra uses technical and organizational measures designed to protect information during transmission and processing.

These measures may include:

  • Encryption of data transmitted over public networks using industry-standard security protocols;
  • Secure management of passwords, authentication credentials, access tokens, and encryption keys;
  • Restricted access to production systems and customer information;
  • Protected backup and recovery processes;
  • Secure file-transfer methods; and
  • Logical controls designed to limit access to authorized users and systems.

Certain information may be decrypted or otherwise made readable when it is actively processed, displayed to an authorized user, transmitted to an authorized integration, or used to provide the Services.

Customers are responsible for using secure methods when downloading, exporting, transmitting, or storing information outside the Asaterra-controlled environment.

6. Cloud Hosting and Infrastructure

The Asaterra Platform is hosted using Amazon Web Services (AWS) cloud infrastructure. Asaterra may also use established third-party providers for authentication, communications, monitoring, data storage, software development, customer support, and related technology services.

Asaterra selects and manages providers based on factors that may include:

  • Service capabilities;
  • Security practices;
  • Reliability and availability;
  • Contractual protections;
  • Data-processing requirements;
  • Geographic considerations; and
  • The nature of the information being processed.

AWS and other third-party infrastructure providers remain responsible for the security of the systems and services under their control. Asaterra remains responsible for configuring and using those services in accordance with its contractual obligations and reasonable security practices.

The use of AWS does not create a direct contractual relationship between the customer and AWS unless the customer separately contracts with AWS.

7. Customer Environment and Data Segregation

Asaterra uses logical access restrictions intended to prevent one customer from accessing another customer’s information without authorization.

Customer access may be separated through controls including:

  • Organization-specific user permissions;
  • Account and tenant identifiers;
  • Role-based authorization;
  • Application-level access controls;
  • Database or storage permissions;
  • Integration credentials; and
  • Administrative access restrictions.

No customer or user may attempt to access another customer’s environment, information, accounts, integrations, or records without express authorization.

Customer-owned hosting environments, dedicated deployments, or customer-specific configurations may be governed by additional security terms in the applicable customer agreement.

8. Secure Software Development

Asaterra incorporates security considerations into the design, development, testing, deployment, and maintenance of the Services.

Security practices may include:

  • Access controls for source code and development systems;
  • Separation of development, testing, and production environments;
  • Code review;
  • Automated or manual security testing;
  • Dependency and software-component review;
  • Change-management procedures;
  • Testing before production deployment;
  • Protection of development credentials;
  • Logging of material production changes; and
  • Review and remediation of identified security issues.

The timing and priority of remediation may depend on the severity of the issue, likelihood of exploitation, potential impact, availability of a reliable correction, and the risks associated with implementing the correction.

9. Vulnerability and Patch Management

Asaterra maintains processes intended to identify, evaluate, prioritize, and address security vulnerabilities affecting systems under its control.

These processes may include:

  • Security advisories and threat-information review;
  • Software and dependency scanning;
  • Application and infrastructure testing;
  • Cloud-security monitoring;
  • Vendor notifications;
  • Internal review;
  • Customer or researcher reports;
  • Operating-system and software updates; and
  • Risk-based remediation planning.

Not every available update or patch can be installed immediately. Asaterra may evaluate compatibility, operational impact, severity, exploitability, and other risks before deploying an update.

When immediate remediation is not reasonably available, Asaterra may use compensating controls or other risk-reduction measures where appropriate.

10. Logging, Monitoring, and Detection

Asaterra may collect and review system, application, authentication, administrative, audit, integration, and security logs to:

  • Maintain and troubleshoot the Services;
  • Identify unauthorized access;
  • Investigate unusual activity;
  • Detect system failures;
  • Support audit and compliance requirements;
  • Respond to customer questions;
  • Investigate security events; and
  • Improve security and reliability.

Logging capabilities and retention periods may vary by system, customer configuration, contractual requirement, and operational need.

Asaterra does not guarantee that every unauthorized action, error, attack, or security event will be identified immediately or prevented.

11. Administrative and Personnel Security

Access by Asaterra personnel and authorized contractors is limited according to business responsibilities and operational needs.

Security measures may include:

  • Confidentiality obligations;
  • Role-based access;
  • Restricted administrative privileges;
  • Authentication requirements;
  • Security-awareness training;
  • Access approval processes;
  • Separation of duties where appropriate;
  • Logging of privileged activity;
  • Removal of access following termination or role changes; and
  • Review of vendors and contractors with access to systems or information.

Access to customer information may be provided when reasonably necessary to support, secure, troubleshoot, maintain, or improve the Services or to comply with an authorized customer request or legal obligation.

12. Third-Party Service Providers

Asaterra may use third-party providers to support cloud hosting, software development, authentication, monitoring, communications, document storage, customer support, billing, data processing, and other business functions.

Asaterra evaluates service providers according to the nature of the service and the information they may process.

As appropriate, Asaterra may use measures including:

  • Contractual confidentiality requirements;
  • Data-protection terms;
  • Security representations;
  • Restricted access;
  • Provider-security documentation;
  • Periodic review;
  • Incident-notification obligations; and
  • Requirements to return or delete information.

Third-party services are not entirely controlled by Asaterra. A third-party failure, vulnerability, interruption, or security event may affect the availability or security of the Services.

13. Data Backup and Recovery

Asaterra maintains backup and recovery processes designed to support the restoration of systems and information following certain failures, disruptions, or security events.

Depending on the applicable Service, these processes may include:

  • Automated backups;
  • Protected backup storage;
  • Redundant cloud infrastructure;
  • Database recovery capabilities;
  • System-restoration procedures;
  • Periodic recovery testing; and
  • Business-continuity planning.

Backup frequency, recovery capabilities, recovery time, and data-retention periods may vary by system and customer agreement.

Backups are not a substitute for customer-controlled recordkeeping. Customers should maintain independent copies of information when required by law, regulation, customer policy, or operational need.

Unless expressly provided in an applicable customer agreement, Asaterra does not guarantee that all information can be restored without any loss following every type of interruption or event.

14. Security Incident Response

Asaterra maintains procedures intended to identify, evaluate, contain, investigate, remediate, and recover from suspected or confirmed security incidents.

Incident-response activities may include:

  • Initial assessment and classification;
  • Containment of affected systems or accounts;
  • Preservation and review of relevant records;
  • Investigation of the nature and scope of the event;
  • Engagement of technology providers or professional advisers;
  • Credential resets or access restrictions;
  • Remediation and recovery;
  • Customer communication;
  • Legally required notifications; and
  • Post-incident review.

Asaterra will provide customer notification of a confirmed security incident affecting customer information when required by applicable law or an applicable customer agreement.

The timing and content of a notification may depend on the nature of the incident, the availability of reliable information, law-enforcement requests, containment efforts, legal requirements, and the applicable customer agreement.

15. Customer Security Responsibilities

Customers and authorized users must take reasonable measures to protect their access to the Services.

Customers and users should:

  • Use unique and secure passwords;
  • Enable multifactor authentication when available;
  • Protect authentication devices and codes;
  • Avoid sharing accounts;
  • Keep browsers, operating systems, and devices updated;
  • Use secure networks;
  • Restrict access to authorized personnel;
  • Review and update user permissions;
  • Promptly disable former employee and contractor accounts;
  • Verify the accuracy of email addresses and notification recipients;
  • Protect exported or downloaded information;
  • Use approved integrations and application credentials;
  • Report suspicious activity promptly; and
  • Follow applicable organizational security policies.

Users should not enter highly sensitive personal information, regulated information, payment-card information, medical information, government identification numbers, authentication secrets, or other restricted information into the Platform unless the applicable customer agreement and Platform configuration expressly permit that information.

16. Security of Integrations and Connected Systems

Customers may choose to connect the Services to third-party software, equipment, sensors, databases, identity providers, communication services, or other systems.

The security of an integration depends on multiple parties, including Asaterra, the customer, the integration provider, the equipment provider, and the network or systems through which data is transmitted.

Customers are responsible for:

  • Authorizing integrations;
  • Protecting integration credentials;
  • Limiting integration permissions;
  • Confirming that the connected system is appropriate for the intended use;
  • Reviewing the third party’s security and privacy practices; and
  • Disabling integrations that are no longer required.

Asaterra is not responsible for security vulnerabilities or unauthorized access originating within a customer-controlled or third-party system except to the extent expressly stated in an applicable written agreement.

17. Security Testing and Assurance

Asaterra may perform or arrange for security reviews, vulnerability assessments, code analysis, configuration reviews, penetration testing, or other evaluations based on the maturity, scope, and risk profile of the applicable Services.

Any security certification, independent audit, penetration-test result, compliance report, or formal assurance held by Asaterra will be identified only through authorized documentation.

This Security Notice does not represent that Asaterra holds a specific certification, audit report, or regulatory designation unless that certification or designation is expressly stated in writing by Asaterra.

Security reports and detailed technical documentation may contain confidential information and may be provided only to qualified customers under appropriate confidentiality protections.

18. Reporting a Security Concern

Customers, users, and security researchers should promptly report suspected vulnerabilities, unauthorized access, compromised credentials, or other security concerns.

Reports should include, when available:

  • A description of the concern;
  • The affected Service or feature;
  • The date and time the issue was observed;
  • Steps that may reproduce the issue;
  • Relevant screenshots or technical information; and
  • Contact information for follow-up.

Security reports should not include unnecessary customer data, personal information, passwords, access tokens, or other sensitive information.

Reports may be submitted to:

Security Email: security@asaterra.com

A report does not authorize an individual to access data, disrupt systems, conduct testing, exploit a vulnerability, or violate the Terms of Use.

19. Prohibited Security Testing

No individual or organization may perform vulnerability scanning, penetration testing, automated testing, denial-of-service testing, social engineering, credential testing, data extraction, or other security testing against the Services without Asaterra’s prior written authorization.

Authorized testing must remain within the approved scope and must not:

  • Access or alter customer information;
  • Disrupt the Services;
  • Degrade performance;
  • Compromise another account;
  • Introduce malicious code;
  • Retain sensitive information; or
  • Violate applicable law or third-party rights.

Asaterra may suspend or restrict access when it reasonably believes that unauthorized testing or harmful activity is occurring.

20. No Absolute Security Guarantee

Asaterra uses safeguards designed to reduce security risks, but no technology, network, software platform, cloud environment, transmission method, or security program is completely secure.

Asaterra cannot guarantee that:

  • Unauthorized access will never occur;
  • Every vulnerability will be identified;
  • Every attack will be prevented;
  • Every security event will be detected immediately;
  • The Services will always be uninterrupted;
  • Information will never be lost or corrupted; or
  • Every third-party system will remain secure and available.

Customers should evaluate the Services in light of their own security, legal, regulatory, contractual, and operational requirements.

21. Relationship to Customer Agreements

This Security Notice provides a general overview and does not create a separate warranty, service-level commitment, certification, indemnification obligation, or contractual guarantee.

Specific security requirements applicable to a customer may be contained in:

  • A master services agreement;
  • Software license agreement;
  • Subscription agreement;
  • Data processing agreement;
  • Security addendum;
  • Business associate agreement, when applicable;
  • Statement of work; or
  • Other executed written agreement.

If this Security Notice conflicts with an executed agreement between Asaterra and a customer, the executed agreement will control to the extent of the conflict.

22. Changes to This Security Notice

Asaterra may update this Security Notice periodically to reflect changes to:

  • The Services;
  • Security practices;
  • Technology;
  • Legal or contractual requirements;
  • Infrastructure;
  • Service providers; or
  • Business operations.

The revised Security Notice will be posted with an updated effective date.

Material changes will be communicated when required by applicable law or an executed customer agreement.

23. Contact Information

Asaterra, LLC operates as a virtual company and does not maintain a public customer-facing office.

Questions or concerns regarding this Security Notice may be directed to:

Security Email: security@asaterra.com

Privacy Email: privacy@asaterra.com

Legal Email: legal@asaterra.com

Website: asaterra.com

Formal notices must be provided in accordance with the applicable customer agreement.

--END OF SECURITY NOTICE--