Don't take our security on trust. Verify it.
ASTIS is built so infrastructure access doesn't mean data access — storage, encryption, access, and audit live on independent trust boundaries. Here is how that holds, what we've attested, and what you can check yourself.
CASA Tier 2 complete · SOC 2 Type II in progress · EU/EEA data plane · Customer-controlled keys
Verifiable evidence
Proof you can check without trusting us — and live checks from our own infrastructure.
Verifiable signatures
Every release is signed via the same /v1/sign API and verified with gpg — no ASTIS account.
Verify it yourselfLive dogfood
Workload secrets proven end-to-end, backed by 1,912 api-gateway + BFF tests green in CI.
See it workNo plaintext at the edge
Encrypted on your side; the edge sees a capsule and a proof, never business-payload plaintext.
How the boundary holds
Compromising storage, a database, or a backup does not by itself expose plaintext — decryption authority lives separately.
Four independent trust boundaries
Storage, encryption, access control, and audit are separated — a breach of one does not compromise the others.
Customer-controlled key custody
Two modes: ASTIS-managed CVS, or self-hosted HYOK CVS in your own infrastructure — where keys never leave you and ASTIS never sees them. You hold decryption authority.
Tamper-evident audit
Every cryptographic operation is recorded in a hash-chained log; tampering breaks the chain. Export evidence for review or litigation hold.
Attestations & readiness
We do not claim certifications we have not completed. Here is exactly where we stand.
CASA Tier 2
Cloud Application Security Assessment Tier 2 completed. Validation report available under NDA.
SOC 2 Type II
Readiness program in progress — policies, evidence collection, independent audit planning. Letter of readiness under NDA in 2026.
ISO 27001
On the roadmap; controls designed around the ISO 27001 catalogue, no certification yet.
Sector frameworks
We do not claim HIPAA / PCI-DSS / FedRAMP certification. ASTIS is HIPAA-aligned by architecture (PHI never crosses the edge under HYOK); a BAA is available for Enterprise / HYOK CVS.
Data handling & residency
EU/EEA data plane · regional options
ASTIS-managed data plane runs in EU/EEA datacentres on dedicated servers — not public cloud.
- •US / on-prem residency — HYOK CVS runs in your own infrastructure
- •Payloads stay in your systems by design — your mailbox provider, your cluster
- •Key custody — with HYOK: key-release decisions and their audit trail — sits in the region you control
Regional separation is architectural, not contractual.
Data minimization
ASTIS processes the minimum required per operation — capsules, hashes, encrypted artifacts, policy metadata, and audit events. Never business-payload plaintext.
Security contact
Report a vulnerability or request our security documentation, CASA report, or DPA under NDA.
We acknowledge reports and coordinate responsible disclosure.