Security
Security and tenant isolation are foundational to Asozal. This page describes how we handle your data, control access, and operate the platform. We describe our practices plainly and route security questions to a dedicated contact.
Data handling and encryption
Customer data is encrypted in transit using TLS and encrypted at rest by our managed database and storage providers. We collect and retain only the data needed to operate the service.
Asozal is designed to help teams manage sensitive vendor, renewal, and spend information with clear access controls and customer ownership of data.
Your vendor records, contract details, renewal dates, spend amounts, workspace notes, and related account information are treated as customer data. Asozal uses this data to provide the product: vendor tracking, renewal planning, cost monitoring, alerts, workspace collaboration, and account reporting.
Asozal does not sell customer vendor records, spend data, contract details, or renewal information.
Access controls
Access to production systems is restricted to authorised personnel on a least-privilege basis and is protected by strong authentication. Administrative actions are logged.
Your data is visible only to authorized users in your Asozal account based on their role and workspace access.
Asozal personnel may access customer data only when needed to provide support, troubleshoot product issues, maintain security, or comply with legal obligations. Internal access is limited by role and business need.
Asozal protects customer data using application access controls, workspace permissions, encrypted HTTPS connections, and managed cloud infrastructure controls.
Production secrets are stored outside the codebase, and customer access is scoped by account, workspace, and user role. Asozal runs on Microsoft Azure and uses managed cloud services for hosting, storage, and application operations.
Customer and workspace isolation
Customers control the users invited into their account and the vendor information they enter into Asozal. Account owners can manage team access, update workspace membership, and remove vendor records that are no longer needed.
Customers may request account-level data export or deletion, subject to legal, billing, and security-retention requirements.
Vendor integrations
Where Asozal connects to vendor or pricing services, credentials are stored securely and used only to retrieve the data you have asked us to monitor. Integrations are scoped to the minimum access required.
Audit posture
We maintain logging and monitoring across the platform and review our security practices on an ongoing basis. We are happy to discuss our current posture and roadmap with prospective customers under NDA.
Subprocessors
We use a small set of subprocessors for hosting, database, and email delivery. Each is contractually bound to protect customer data. A current list is available on request.