Access Controls

Information Security & Access Control

How administrative access to customer systems is protected, controlled, and recorded.

Trust & Compliance Centre · Last reviewed: October 2025

At a glance

Do you enforce multi-factor authentication (MFA) for administrative access to customer systems? Yes MFA is enforced on all administrative accounts
Do you maintain audit logs of administrative access and changes to customer systems? Yes Platform, identity, and source-control audit trails are retained

Multi-factor authentication

Multi-factor authentication is enforced for all administrative access to systems that host or process customer data. This includes:

  • Cloud management — Azure subscriptions and the Azure portal, protected by Microsoft Entra ID with MFA enforced on administrative accounts.
  • Source control and CI/CD — repository hosting and deployment pipeline platforms, with MFA required on all accounts holding write or release permissions.
  • Supporting services — email delivery, content management, and any third-party service with access to customer environments.

Administrative access uses named, individual accounts. Shared credentials are not used for administrative activity, so every action is attributable to a specific person.

Least privilege and access management

  • Access to customer systems is granted on a least-privilege basis using role-based access control (RBAC), scoped to the environments and resources each role requires.
  • Production access is limited to those who need it for the engagement; development and test environments are separated from production.
  • Access is reviewed periodically and on role change, and revoked promptly when a team member or contractor leaves an engagement.
  • Secrets and connection strings are held in managed stores (such as Azure Key Vault) rather than in code, configuration files, or shared documents.
  • Fully remote, cloud-based estate — we operate fully remotely over secure VPN; our estate and development environments are entirely cloud-based and protected, with no on-premise servers or office network holding customer data.

Audit logging

Administrative access and changes to customer systems are recorded across several complementary audit trails:

  • Azure Activity Log — records administrative operations on cloud resources (creation, configuration changes, deletions), including who performed them and when.
  • Microsoft Entra ID sign-in and audit logs — record authentication events and identity changes for administrative accounts.
  • Source control history — every code change is version-controlled and attributable, with protected branches preventing unreviewed changes reaching release.
  • Deployment pipeline logs — every release to a customer environment is recorded, including the version deployed, who approved it, and when.
  • Application logging — solutions are built with application-level logging and monitoring (such as Azure Application Insights) appropriate to the engagement.

Log retention periods follow platform defaults as a minimum and are extended where an engagement requires it. Logs relevant to a customer's own systems can be made available to that customer on request.

Full policy available on request

The complete access control policy — including specific control configurations — is not published, as the detail would be useful to an attacker. It is available to customers under NDA via hello@assemblysoft.com.

Back to the Trust & Compliance Centre

Start a meaningful conversation with us today.

FAQs

Assemblysoft are Your Safe Pair of Hands

Microsoft Azure

Azure

Azure DevOps

Azure DevOps

Blazor

Blazor