Trust centre
Security
Security work is mostly invisible when it's done right. Here's what we do, what we're working towards, and how to tell us if you find a problem.
Security practices
Encrypted everywhere
Data is encrypted in transit (TLS) and at rest. There is no unencrypted copy of your family's data anywhere in our system.
UK hosting
The whole service runs in Microsoft Azure's UK South region: hosting, database, storage, background jobs, AI, email and monitoring. Your child's profile, answers and reports are processed in the UK, in Microsoft Azure. The only thing processed outside the UK is usage analytics (PostHog, EU): it's linked to a session, not your name, and it never receives your child's profile, answers or reports. The subprocessor register lists every provider.
Least-privilege access
Access to production data is limited to the small number of people who need it to run the service, and every access path is authenticated.
Secure development
Every change is reviewed and passes automated checks before release. Dependencies are monitored and security patches applied promptly.
Isolation by design
Each family's data is segregated by account. The architecture enforces tenant isolation at the database layer, not just in application code.
If something goes wrong
If a breach ever affects your family's data, we tell you, even where UK GDPR wouldn't strictly require it, and notify the ICO where required: what happened, what it means, and what we've done.
Independent assurance, where we are, honestly
As part of preparing to work with NHS services, we're working through the NHS Digital Technology Assessment Criteria (DTAC 2.0), the Data Security and Protection Toolkit (DSPT), Cyber Essentials certification and independent penetration testing. We'll state each one here as complete when it is, and not before. If you're an NHS or school information-governance team and want the current status in detail, email ayse@getassembly.co.uk and we'll share our assessment pack.
Found a vulnerability?
We want to hear about it, and we won't take legal action against good-faith research. Email info@helloassembly.com with enough detail to reproduce the issue. We'll acknowledge your report, keep you updated as we fix it, and credit you if you'd like. Please don't access other people's data while testing, use your own account. This policy is also referenced from /.well-known/security.txt .