Security Policy
Asterolabs accesses clients' systems, code, credentials, and data during engagements — especially in cybersecurity. This policy describes the technical and organizational measures we adopt to protect that access and information.
1. Scope
This Security Policy applies to the handling of information within Asterolabs' services — Automation + AI and Cybersecurity — including access to clients' systems and environments, the operation of automations hosted by Asterolabs, and the data processed in each engagement.
The policy covers the infrastructure, systems, staff, and partners involved in delivering the services.
2. Protected Assets
The measures in this policy protect, depending on the engagement:
- Client credentials and access: keys, tokens, passwords, and other access granted to Asterolabs to deliver the service.
- Client systems and code: environments, repositories, and applications Asterolabs accesses during assessments and development.
- Client data: business data and personal data accessed or processed while delivering the service.
- Hosted automations: the workflows and integrations Asterolabs operates on its infrastructure.
- Asterolabs' internal assets: source code, tools, configurations, and proprietary information.
3. Security Principles
Asterolabs follows these principles:
- Confidentiality: access to information restricted to the people and systems strictly necessary to deliver the service.
- Integrity: protection against improper alteration of data and systems.
- Availability: effort to keep contracted automations operational while the service is active.
- Least privilege: access limited to what is necessary and for as long as it is necessary.
- Transparency: clear communication about how access and data are handled.
4. Credentials and Access to Third-Party Environments
Because Asterolabs frequently accesses clients' own environments, credential and access handling follows specific safeguards:
- Credentials granted by the client are stored securely, with access restricted to the team responsible for the engagement.
- The principle of least privilege applies: we request only the access needed for the contracted scope.
- Wherever possible, we prefer named, temporary, and revocable access over shared credentials.
- When the engagement ends, granted access should be revoked by the client, and the corresponding credentials are discarded by Asterolabs.
- Security testing and intervention in a client's environment are performed only within the scope and the client's formal authorization.
5. Security Measures
Asterolabs implements multiple layers of protection:
- Encryption: data in transit protected by TLS. Sensitive data and credentials at rest are protected by encryption (AES-256).
- Authentication: use of multi-factor authentication (MFA) and strong passwords on Asterolabs' accounts and tools.
- Access control: a least-privilege model and role-based access control (RBAC) for staff and internal systems.
- Infrastructure: hosting with cloud providers holding recognized certifications (SOC 2, ISO 27001), with a web application firewall (WAF) and protection against known threats on hosted automations.
- Monitoring: logging and monitoring of relevant access and activity.
- Backups: where applicable to the hosted automation, backups with secure storage.
- Secure development practices: code reviews and security care when building automations.
6. Client Responsibilities
Security is a shared responsibility. We recommend that the client:
- Grant Asterolabs only the access needed for the contracted service.
- Use strong passwords and multi-factor authentication on its own systems.
- Rotate or revoke granted access when the engagement ends.
- Keep the systems and environments under its responsibility up to date.
- Report any suspicious activity related to the service immediately.
7. Security Incidents
In the event of a security incident affecting personal data, Asterolabs undertakes to:
- Promptly notify the affected client and, where Asterolabs acts as controller, notify the relevant authorities and individuals within the timeframes required by applicable law.
- Where Asterolabs acts as processor, support the client (controller) in assessing, communicating, and responding to the incident.
- Investigate the cause and implement corrective measures.
- Document the incident, the data affected, and the actions taken.
To report vulnerabilities or incidents, contact us at support@asterolabs.com.
8. Limitations
Although Asterolabs applies rigorous measures, no system is completely immune to risk. Therefore:
- Asterolabs does not guarantee absolute security against all possible threats.
- Asterolabs is not liable for incidents arising from vulnerabilities in the client's own systems that are outside the contracted scope, or from access improperly retained after the engagement ends.
- Asterolabs works continuously to improve its defenses and respond quickly to new threats.
9. Contact
For questions about the security of Asterolabs' services, contact us: