// Help / Account & Data
Security & Data: Where Your Asset Data Lives
If you're about to hand over your company's entire IT inventory to a piece of software, you probably want to know where it goes and who can see it. Fair. Here's the actual answer, not a page full of compliance logos.
Where Your Data Lives
AssetCompass is built on Supabase, which runs on AWS. Your data is stored in a managed PostgreSQL database in the US East (N. Virginia) region. There is no option to choose a different region right now — if that's a hard requirement for you, let us know.
Files you upload (receipt images, asset photos) are stored in Supabase Storage, which also runs on AWS infrastructure in the same region.
Encryption
Two layers:
- In transit — all traffic between your browser and AssetCompass is encrypted with TLS. The connection is HTTPS only; there's no HTTP fallback.
- At rest — the underlying database volumes are encrypted at rest by AWS. This is managed by Supabase and on by default.
We don't store passwords. Authentication is handled by Supabase Auth, which uses bcrypt hashing for credentials. We never see your password in plaintext.
Org Isolation: Who Can See What
Every piece of data in AssetCompass — assets, people, locations, events — is scoped to an organization. The database enforces this with Row Level Security (RLS), which means the database itself (not just the application) checks that you belong to an org before returning any of that org's data.
The practical result: even if there's a bug in the application layer, a user in Org A cannot read, write, or accidentally access data belonging to Org B. The isolation is enforced at the database level, not just in code.
Who at AssetCompass Can See Your Data
We have access to the production database for support and debugging purposes. We don't browse customer data as a matter of practice, and we don't sell it. If you report a bug that requires looking at your data to diagnose, we'll tell you before doing so.
We're a small team. There's no large workforce of analysts with access to your inventory — it's the founders and, eventually, engineers working on the product.
Authentication and Sessions
AssetCompass uses email/password authentication. Sessions are managed via JWTs issued by Supabase Auth and stored in your browser. Sessions expire automatically and are invalidated on logout.
- Password reset is available from the login page — a reset link is sent to your email
- There's no SSO or SAML support yet — it's on the roadmap for larger teams
- Multi-factor authentication is not currently available — also on the roadmap
Roles and Access Within Your Org
Within your organization, access is controlled by role — Admin or Viewer. Admins can see and modify everything. Viewers can read but not write. Neither role can access other orgs. See the inviting your team guide for the full breakdown.
Data Retention and Deletion
If you cancel your subscription, your data is retained for 30 days in case you change your mind. After 30 days, it's deleted. We don't archive it, sell it, or use it for training models.
You can export all your data at any time from the Assets, People, and Locations pages — no need to cancel to get your data out. See the cancellation and exports guide.
More Questions?
Our Privacy Policy has the formal language. If you have specific security questions not covered here — penetration testing results, sub-processor list, specific compliance requirements — reach out directly at hello@assetcompass.co.