Assessments about people are sensitive. The product is built around that.
Everything on this page is a property of how Aspen is constructed. Where a control is a mechanism rather than a policy, the mechanism is described.
- Multi-tenant with hard isolation
Every query is tenant-scoped. There is no path in the application that reads across tenants.
- Default-deny
Access is denied unless a role grants it. Membership of a tenant, on its own, grants nothing.
- Identity administration is separate from change data
The admin role, typically held by IT, manages single sign-on and security settings and cannot see change data at all. Change managers hold the change data and do not hold identity administration. We recognise the risk of IT seeing sensitive change data and we built Aspen's Role Based Access Control to avoid it.
- Stakeholders see a curated view
Stakeholders don't normally log into Aspen, but you can publish reporting for them to consume. Either way, they never see sentiment, and never see assessments about themselves.
- Confidential by default
Nothing is visible across the organisation unless a change manager deliberately publishes a single dashboard. The publish action warns before it completes.
- Minimum group size of five
No sentiment or training-needs aggregate renders for a group under five people. A small team is never identifiable from its own results.
- Pulse survey anonymity
Pulse survey anonymity is configurable per survey. When a survey is private, who was invited is stored separately from what was answered.
- Roles, not people, in the org tree
The leaf the org tree is a role. Impact ratings are held against roles and teams, not against named individuals.
- MFA for every user
Multi-factor authentication is mandatory, using time-based one-time passcodes or passkeys. SMS is not offered.
- SAML single sign-on
Available on the Enterprise tier. The Standard tier uses Aspen's own authentication, with invite-only access.
- Append-only history
Reassessments, sentiment snapshots and audit events are appended, never overwritten. The record of what was believed and when is kept.
- Type changes are non-destructive
Renaming or retiring an impact type, a sentiment label or a change phase never destroys an in-flight record that uses it.
Ask us the hard ones.
Security reviews are a normal part of how Aspen is sold. If your organisation has a questionnaire, an architecture review or a data-handling standard, we're happy to help.
Bring your security review
We will walk through the tenant model, the role model and the data-handling posture with your security team, on a call or in writing.