Our mission

LambdaAssetCheck helps organizations run safer, more compliant field operations through structured inspections, asset management, and work follow-through. Teams worldwide rely on our platform to capture evidence in the field, track corrective actions, and prove compliance — online or offline.

Certifications

We take cybersecurity seriously. Our active, continually improving security program protects customer data and the services we provide. We are transparent about formal attestations — details below reflect our current status.

Aligned — certification in roadmap

ISO 27001

Information security management

We align our security program with ISO 27001 control areas — access management, encryption, incident handling, and vendor review. Formal ISO 27001 certification is not yet complete; we can share our control documentation for vendor assessments.

In progress

SOC 2 Type II

Trust Services Criteria

Our controls are designed around the AICPA Trust Services Criteria for security and availability. We are not yet SOC 2 Type II certified. Enterprise customers can request a security questionnaire response or architecture overview while formal attestation is in progress.

We also follow data-protection practices aligned with GDPR and CCPA where applicable. A Privacy Policy and Data Processing Agreement are available on request via legal@lambdaassetcheck.com.

Key features

Internal controls & policies

Aligned with recognized security practices

LambdaAssetCheck maintains security policies and engineering standards that are reviewed as the platform evolves. Access to production systems is limited to authorized personnel. Role-based permissions, site-scoped data access, and organization isolation enforce least privilege for every customer tenant.

  • Fine-grained RBAC with custom org roles and site-level scoping
  • Route-level authorization on every sensitive page and API
  • Third-party subprocessors reviewed before integration
  • Server-side input validation and parameterized database queries
  • Centralized client and server logging for investigation

Protecting customer data

Committed to data protection and privacy

Customer data is stored in isolated, org-scoped production environments. Access is restricted to essential operations and support workflows authorized by the customer. Data is encrypted in transit with TLS and protected at rest through managed cloud infrastructure and application-level encryption for integration secrets.

  • Passwords hashed with bcrypt; API tokens stored as secure hashes
  • AES-256-GCM encryption for integration and SSO client secrets
  • OIDC single sign-on available on Professional plans and above
  • Operational audit trails for inspections, flags, work, and incidents
  • Data Processing Agreement available on request for enterprise customers

Scalable and reliable

Built on managed cloud infrastructure

Production runs on Kubernetes with horizontally scaled application pods. PostgreSQL and object storage are provided by managed cloud services (Oracle Cloud Infrastructure or DigitalOcean, depending on deployment). This architecture lets us scale with customer demand while inheriting provider security controls for physical and network layers.

  • Multi-pod deployment with health checks and auto-scaling
  • Managed PostgreSQL with connection pooling and bounded concurrency
  • S3-compatible object storage for inspection media and documents
  • Rate limiting backed by PostgreSQL so limits hold across all instances

Clear incident management

Prepared to respond and communicate

We monitor application health and error logs to detect issues early. When a security incident affecting customer data is confirmed, we investigate promptly and notify affected customers in line with applicable law and contractual obligations. Our support organization is available for urgent product and security concerns.

  • Documented incident response workflow for security events
  • Responsible disclosure process for vulnerability reports
  • Customer notification for confirmed data-integrity or availability incidents
  • Disaster recovery through replicated infrastructure and managed database backups

API & integration security

Secure connections to your broader stack

Organizations integrate LambdaAssetCheck with CMMS, HR, and mobile workflows through our REST API. API keys are org-scoped, hashed at rest, and rate-limited. Downstream integration credentials are encrypted with organization-specific keys so one tenant’s secrets cannot decrypt another’s.

  • Bearer token and Basic Auth support with hashed credential storage
  • Per-key API rate limits with 429 responses and retry guidance
  • Login throttling to reduce brute-force and credential-stuffing risk
  • Webhook signature verification for payment and platform events

Subprocessors

The following third-party services may process customer data when you use LambdaAssetCheck. Your deployment may use a subset depending on hosting configuration.

ProviderPurposeLocation
Oracle Cloud Infrastructure (OCI)Application hosting, managed PostgreSQL, and object storage (when deployed on OCI)Customer-selected region
DigitalOceanApplication hosting, managed PostgreSQL, and Spaces object storage (when deployed on DigitalOcean)Customer-selected region
ResendTransactional email (invitations, notifications, password reset)United States
RazorpayPayment processing for subscriptions and billing (billing contacts only)India

LambdaAssetCheck considers cybersecurity a fundamental part of our business and the products we provide globally. While this summary outlines our multifaceted security approach, we maintain extensive controls and measures beyond what is covered here. For further details or questions about our support, security, or privacy practices, please contact us directly.

To report a security incident, contact security@lambdaassetcheck.com. For product support, visit Contact us.

Last updated: July 2026

Top