| COMPLIANCE FEATURE | ASSEMBLA | GITHUB |
|---|---|---|
| SOC 2 Type II | All plans | Enterprise only ($21/user/month) |
| GDPR compliance | All plans, EU data residency available | Enterprise Cloud only |
| IP whitelisting | Enterprise single-tenant (Git, SVN, Perforce) | Enterprise Cloud only |
| SAML SSO | All plans (platform access) | Enterprise only |
| Audit logs | Available on request (all plans) | Basic (all plans) / API (Enterprise only) |
| SVN & Perforce support | All plans | Not supported |
| Single-tenant hosting | Available on all products | Enterprise Server (self-managed only) |
Both platforms hold SOC 2 Type II certification. The key difference is availability: Assembla includes SOC 2 and GDPR compliance in every plan. GitHub reserves these controls for Enterprise Cloud at $21/user/month. For teams that need compliance across Git, SVN, and Perforce in a single environment, Assembla is the only option. GitHub does not support SVN or Perforce.
Yes. Assembla holds AICPA SOC 2 Type II certification across all areas of our source code management platform. SOC 2 Type II is an audit conducted over an extended period by a licensed CPA from the AICPA. It assesses the effectiveness of our internal security controls across the security, availability, and confidentiality Trust Services Criteria. Full documentation is available on request for your procurement and legal teams.
Yes. We comply with GDPR data protection principles including consent for data collection, granular access controls, full auditability, and the right to erasure. Customers with EU data residency requirements host their repositories in our Frankfurt, Germany region. All EU personal data is processed in compliance with GDPR. Full GDPR documentation is available on request.
All data stored on Assembla uses AES-256 encryption at rest on AWS infrastructure. Data in transit uses SSL/TLS encryption. Physical security at our data centers in Ohio (US), Frankfurt (Germany), and Mumbai (India) is managed by AWS staff under their shared responsibility model.
Assembla provides RBAC natively across Git, SVN, and Perforce. SVN and Perforce access controls work at the folder, branch, and file level, allowing organizations to restrict specific repositories or assets to individual contractors or teams. Branch protection rules prevent unauthorized merges. IP whitelisting restricts repository access by network. Audit logs are available on request for legal and compliance purposes.
When you delete data on Assembla, we retain copies for one month to allow for recovery of repositories or project management assets. After that period, data is permanently removed. Daily automated backups and S3 bucket support are included in every plan. Enterprise environments support custom backup schedules and retention policies configured to your specific recovery requirements.