Encrypted in transit,
encrypted at rest, sealed twice.
The facts, as they are in the product today. Nothing on this page is a plan.
What protects your data,
and your customers’ data.
In transit
TLS 1.2 or later on every connection, enforced at the edge with HSTS, and on every call the platform makes to Microsoft, Google, Intuit, Resend, Autotask and the rest. The collector posts over HTTPS only; nothing listens on a customer's machine.
At rest
The database, file store and key store are encrypted at rest by the platform provider. On top of that, every stored credential and token (mail keys, phone system, Pax8, Datto, Autotask, QuickBooks, Microsoft and Google tokens, cloud keys) is sealed a second time with a key held outside the database, so a copy of the database exposes none of them. Private files are served only through a signed or signed-in path, never a public link.
Sign-in and access
The dashboard sits behind an identity-aware edge with single sign-on (Microsoft or Google). Customer portals use one-time codes or Sign in with Microsoft or Google; no passwords are stored anywhere. Every sign-in, refusal and privileged action is written to an access log the customer can export.
The edge
Served by Cloudflare: DDoS protection, a web application firewall, bot management and rate limiting in front of every request; United States data residency; nightly database copies kept for ninety days.
Regulated work
No CUI is stored by design: an attachment marked CUI is deleted on arrival and the sender told to keep it in the enclave. Tenant actions run as the customer's own administrator inside the customer's own tenant. Enclave work is restricted to cleared people and a Global Administrator account is refused on an enclave. The FedRAMP position and where the platform sits are documented for the customer's assessor.
Your data
You own it. Export it at any time. Close the account and it is deleted thirty days later. Nothing is sold, nothing is used for advertising.
The platform is evidence
for your own assessment.
The access log and the ticket audit export are a CMMC evidence trail; every tenant action names the technician, the tenant and the user; the assessor seat shows what an auditor saw and when. Section 9 of the Operator Guide states where Asteroniq sits against FedRAMP and CMMC for your C3PAO.
Questions an assessor would ask?
Ask them.
We answer security questionnaires with the facts above and the documentation behind them.