Skip to main content

Trust

How AssetStacc protects your fleet data

What we actually do to keep one business's records separate, private and recoverable — and what we do not claim.

Who operates the platform

The AssetStacc Platform is operated by AssetStacc Incorporated. This page was last reviewed on . It describes the controls in place today. See about AssetStacc for company identity and legal for terms and privacy.

Controls in place

Separation between businesses

Every record — asset, inspection, work order, invoice, document — belongs to one business account. Access rules are enforced by the database itself on every read and write, not only by the screens, so one business cannot read or change another business's records.

Role-based access inside an account

Owners, managers, technicians and customer-portal users see different fields. Customer-portal users can view and confirm their own work, but cannot change internal pricing fields, technician assignment, scheduling controls, staff notes or workflow status.

Encryption in transit and at rest

The application, API and customer portal are served only over HTTPS by our hosting provider, Lovable Cloud, so data moving between your browser and AssetStacc is encrypted in transit. Data stored in the database and in file storage is encrypted at rest by that same hosting platform. These are platform services we rely on, not controls AssetStacc implements itself.

Private file storage by default

Uploaded photos, inspection reports, receipts and documents are stored in private buckets. Nothing is publicly listable by URL; files are reached through time-limited authorised links tied to the requesting account. Download links are created only after an authorisation check and expire after 10 minutes; anyone holding an unexpired link can use it, so links should not be forwarded or shared.

Upload screening

Upload restrictions are enforced primarily by AssetStacc's application layer. All storage buckets are private. Some buckets also have bucket-level file-size limits, but several do not, and bucket-level MIME allowlists are not currently configured across all buckets. Before a file is stored, AssetStacc checks the allowed file type and extension for that area, a matching file signature read from the actual bytes, a size limit, and a rate limit. Executable, script and disguised double-extension files are rejected, and anything rejected is removed rather than kept. AssetStacc does not currently provide antivirus or third-party malware scanning on uploaded files.

Audit logging

Record changes, approvals, confirmations and administrative actions are written to an audit trail that ordinary users cannot edit or delete, so a record's history can be reconstructed after the fact. Audit entries are retained for the life of the account; we do not automatically delete them, and we do not currently publish a fixed retention window.

Administrative account protection

Platform-level administrative accounts — the AssetStacc staff accounts that can act across the platform — require a time-based second factor in addition to a password, and their actions are logged. Two-factor authentication is not yet required for ordinary business user accounts.

Backups

The database is backed up automatically by our hosting provider, Lovable Cloud. Backup frequency and retention are set by that platform, not by AssetStacc, and we do not state a recovery-point or recovery-time commitment.

What backups do not include

Database backups and data exports cover database records only. Files you upload — photos, inspection PDFs, receipts, documents — live in separate file storage and are not included in a database backup or export. Keep your own copies of anything you cannot replace.

Restore testing

We have run and documented a restore drill against our test environment: a full snapshot, deliberate changes, then a verified restore back to the recorded state, with the recovery time and every finding written down. That drill restored in place, within the same database. Restoring into a separate, isolated environment has not yet been verified, and provider-level point-in-time restore is currently in-place only.

Payment data

Card details are handled by our payment processor. AssetStacc records that a payment happened and its reference; full card numbers are not stored in the AssetStacc database.

Incident response

A written incident-response plan defines detection, containment, recovery, evidence preservation, escalation and customer communication. The plan has been rehearsed twice as documented tabletop exercises against realistic scenarios; both were rehearsals, not real incidents.

Who provides what

AssetStacc provides: separation between business accounts, role permissions, portal field restrictions, upload screening, the audit trail, administrative two-factor, and the incident-response process. Lovable Cloud provides: hosting, HTTPS, encryption at rest, automated database backups and the underlying database and file-storage platform.

What we do not claim

  • AssetStacc does not currently hold a SOC 2, ISO 27001 or any other third-party security certification, and we do not claim one.
  • An independent external penetration test has not yet been completed. When it is, this page will say so and give the date.
  • We do not publish a hosting location, uptime target, or availability, recovery-point or recovery-time commitment.
  • No security programme removes all risk. These are the controls we operate, described plainly, not a guarantee against every possible attack.

Your data, your control

Your records belong to your business. You can export the data you have entered, and you can request deletion of your account data. What we collect and how it is used is set out in the privacy policy, and website tracking is described in the cookie policy.

Reporting a security issue

If you believe you have found a vulnerability or have seen data you should not have access to, email info@assetstacc.com with the details and how to reproduce it. Please do not publish it before we have had a chance to respond. We will acknowledge the report, investigate, and tell you what we found.

Questions before you put your fleet on it?

Ask us anything about access, storage or exports — we will answer in plain terms.