AspenRequest a demo
Security and trust

Assessments about people are sensitive. The product is built around that.

Everything on this page is a property of how Aspen is constructed. Where a control is a mechanism rather than a policy, the mechanism is described.

Isolation and access
  • Multi-tenant with hard isolation

    Every query is tenant-scoped. There is no path in the application that reads across tenants.

  • Default-deny

    Access is denied unless a role grants it. Membership of a tenant, on its own, grants nothing.

  • Identity administration is separate from change data

    The admin role, typically held by IT, manages single sign-on and security settings and cannot see change data at all. Change managers hold the change data and do not hold identity administration. We recognise the risk of IT seeing sensitive change data and we built Aspen's Role Based Access Control to avoid it.

  • Stakeholders see a curated view

    Stakeholders don't normally log into Aspen, but you can publish reporting for them to consume. Either way, they never see sentiment, and never see assessments about themselves.

Confidentiality
  • Confidential by default

    Nothing is visible across the organisation unless a change manager deliberately publishes a single dashboard. The publish action warns before it completes.

  • Minimum group size of five

    No sentiment or training-needs aggregate renders for a group under five people. A small team is never identifiable from its own results.

  • Pulse survey anonymity

    Pulse survey anonymity is configurable per survey. When a survey is private, who was invited is stored separately from what was answered.

  • Roles, not people, in the org tree

    The leaf the org tree is a role. Impact ratings are held against roles and teams, not against named individuals.

Authentication
  • MFA for every user

    Multi-factor authentication is mandatory, using time-based one-time passcodes or passkeys. SMS is not offered.

  • SAML single sign-on

    Available on the Enterprise tier. The Standard tier uses Aspen's own authentication, with invite-only access.

Record integrity
  • Append-only history

    Reassessments, sentiment snapshots and audit events are appended, never overwritten. The record of what was believed and when is kept.

  • Type changes are non-destructive

    Renaming or retiring an impact type, a sentiment label or a change phase never destroys an in-flight record that uses it.

Questions

Ask us the hard ones.

Security reviews are a normal part of how Aspen is sold. If your organisation has a questionnaire, an architecture review or a data-handling standard, we're happy to help.

Talk to us

Bring your security review

We will walk through the tenant model, the role model and the data-handling posture with your security team, on a call or in writing.