Security

Security

A short, factual overview of how we protect your account and data. No system is completely secure.

What we do

  • AssetUpside runs on managed cloud infrastructure, not on office computers.
  • Connections use HTTPS, and the site sends standard browser security headers.
  • Database access rules limit each account to its own data and the deals shared with it.
  • Uploaded documents and photos are stored privately and opened through short-lived links.
  • Two-step sign-in is available to every user and required for our staff admin tools.
  • Sign-in and password-reset attempts are rate-limited.
  • Staff access to customer data is limited by role and logged.
  • Card details are handled by our payment processor; we do not store full card numbers.

What you can do

  • Turn on two-step sign-in in Settings and use a unique password.
  • Remove teammates who no longer need access, and review share links you have sent.
  • Do not upload Social Security numbers, health records or full payment card numbers.

Report a security issue

Email security@assetupside.com with a description, steps to reproduce, and any affected URLs. Please give us reasonable time to investigate and fix the issue before sharing it publicly, avoid accessing or changing other people's data, and do not run tests that degrade the Service. We will not pursue action against good-faith research that follows these guidelines. We do not currently offer paid bug bounties.