• security

Your code and collaboration data deserve the highest protection.

At Assembla, security and data protection come first. See how we help 1 million users in 100 countries manage their repositories and project data.
Verified by trusted security organizations.
AICPA SOC 2 Type II
Assembla passes rigorous annual evaluations of its internal controls, performed by third-party auditors, around data security, availability, integrity, and privacy.
GDPR
Assembla exceeds GDPR principles by always obtaining consent to collect data and implementing robust security measures with access controls. You can always erase personal information.
Privacy Shield
Assembla meets strict data protection requirements for all transfers of personal data between the European Union and United States.
  • INtegrations

Data protection at every layer.

Data Protection

Full encryption

Assembla stores data with AES 256-bit encryption and leverages SSL for all data in transit.

Passwords are never stored directly in the database.
Data Protection

In-house DevOps

Assembla’s DevOps team works 24/7/365 to continuously improve our data protection practices and continuously observe network access/traffic with real-time intrusion monitors.
Data Protection

Restricted production access

Access to production infrastructure is limited to VPNs with specific user accounts and credentials.



Physical security is provided by AWS staff in Ohio, USA; Frankfurt, Germany; or another region based on your managed hosting instance.
Data Protection

Protected APIs

Our developer API uses proven OAuth 2.0-based authentication methods like encrypted API keys and three-step authentication flows.
Data Protection

No compromise

No threat actor has ever compromised Assembla’s cloud infrastructure in more than 18 years in operation.
  • Covered

Disaster recovery is covered.

Geographic distribution
Assembla operates from multiple redundant facilities for performance, availability, and failover options in an outage or data loss scenario.
Hourly backups
On-demand backups to a public cloud provider is our first step in disaster recovery.
Replication
Multiple servers within the same data center replicate new or changed data in real-time.
Multiple failovers
We sync your code and collaboration data to a failover server in the same data center within 30 minutes, then to a disaster recovery cluster in a different region for the highest guarantees your data is safe.
Data retention
When you delete data, we retain copies for a month to allow for recovery of deleted repositories or project management assets.
Complete protection
For every bit written by you, we write it at least 16 more times for redundancy and backups.
  • INtegrations

Accessible features to help you solidify your security posture.

Easy audit reports
View reports of user activity like repository access, merge requests, pushes, and more and export in audit-friendly formats. 
Built-in static analysis
Enable Assembla’s vulnerability scanner to identify possible credential leaks and other security issues before they’re merged.
Multiple authentication options
Manage user accounts with AD/LDAP, then enforce single sign-on (SSO) using SAML 2.0, multi-factor authentication, and your trusted identity provider.
Advanced user controls
Advanced user controls
Limit access to projects and repositories based on user type, protect your branches by requiring multiple reviews, and configure notifications when anyone makes key changes to your source code.

Assemble a secure SCM+PM platform in less than a minute.

Let Assembla handle the DevOps complexity of a merged source code and project management platform. Focus your technical and creative talent on assembling your next big project.
  • Security & Compliance

Source code security that never compromises.

In more than 20 years of operation, no threat actor has ever compromised Assembla's cloud infrastructure. We protect Git, SVN, and Perforce repositories with the same security stack, for every customer, from day one.
SOC 2 Type II · GDPR · EU-US Data Privacy Framework (DPF) · AES-256
Source code security that never compromises.
  • SOC 2 Type II certified
  • GDPR compliant
  • AES-256 encryption
  • IP whitelisting
  • US, EU & APAC regions
  • 20+ years, zero compromises

20+

Years in operation. Zero infrastructure compromises.
We have operated source code hosting for Git, SVN, and Perforce since 2005. No threat actor has ever compromised Assembla's cloud infrastructure in that time. Security is not a feature we added. It is the foundation we built on.
  • Compliance certifications

Your source code repository,
independently verified.

Our certifications are not self-assessments. They are independently audited by third parties against the most rigorous security standards in the industry. Full documentation is available on request for your procurement and legal teams.
Read our source code security guide
  • Use case A: Multi-VCS teams
AICPA SOC 2 Type II
Assembla holds a SOC 2 Type II certification demonstrating compliance with the AICPA's security, availability, and confidentiality criteria. Type II is an audit conducted over an extended period by a licensed CPA, not a point-in-time snapshot.
  • Use case B: Git + PM teams
GDPR
We comply with GDPR data protection principles: consent for data collection, granular access controls, full auditability, and the right to erasure. Customer data in EU deployments stays in Frankfurt, Germany. All EU personal data is processed in compliance with GDPR.
  • Use case C: Compliance teams
EU-US Privacy Shield
Assembla meets strict data protection requirements for transfers of personal data between the European Union and the United States. Full compliance reports are available on request.
  • Access & Authentication

Access control and data protection

at every layer.

Security is not an add-on tier with us. Every Assembla environment ships with the same access controls, encryption, and authentication options. From day one, for every customer.

We support single sign-on via SAML 2.0, OAuth 2.0, and two-factor authentication across all plans. AD/LDAP integration handles user account management. For Perforce environments, we enable SSO and SAML via Perforce extensions at your request at no additional charge.

Assembla provides RBAC natively across Git, SVN, and Perforce. SVN and Perforce access controls work at the folder, branch, and file level. Restrict specific repositories or assets to individual contractors or teams without complicated workarounds.

We log every access event, code change, merge request, and administrative action. Audit reports are provided on request by our DevOps team, for example for legal or compliance purposes.

Restrict repository access by network. IP whitelisting is available across all Assembla environments. For Enterprise single-tenant customers running Git, SVN, or Perforce, we also enforce whitelisting at the AWS Security Group level, which provides the most effective network-layer enforcement.

Branch protection rules prevent unauthorized merges and enforce mandatory review workflows. Git repositories automatically scan every commit for hardcoded secrets, API keys, and passwords before they reach production.

Access to production infrastructure is limited to VPNs with specific user accounts and credentials. Physical security is provided by AWS staff in our data centers.
  • Encryption & Infrastructure

Encryption on by default. No configuration required.

  • 01
AES-256 encryption at rest
All data stored on Assembla uses AES-256 encryption at rest on AWS. Data in transit uses SSL/TLS encryption. This applies to every repository, every project management record, and every file across Git, SVN, and Perforce environments.
  • 02
Globally distributed AWS infrastructure
Repositories deploy in the AWS region closest to your team: US (Ohio), EU (Frankfurt), and APAC (Mumbai). Enterprise Cloud customers can specify any available AWS region. Data residency requirements are configured during scoping, not left as defaults.
  • 03
Protected API access
Our developer API uses OAuth 2.0-based authentication with encrypted API keys and multi-step authentication flows. Access to production infrastructure is limited to VPNs with specific user accounts and credentials.
Source code security that never compromises.
  • Disaster Recovery

Backups, replication, and failover.

Your data survives whatever happens.

We operate from multiple redundant facilities. Automated backups, real-time replication, and geographically distributed infrastructure mean your data has a recovery path whatever happens.

Assembla operates from multiple redundant AWS facilities for performance, availability, and failover options in any outage or data loss scenario.

Daily automated backups to S3 bucket are included in every plan. Enterprise environments support custom backup schedules aligned to your recovery time objectives.

Multiple servers within the same data center replicate new or changed data in real time. We sync your code to a failover server within the same data center within 30 minutes, then to a disaster recovery cluster in a different region.

Assembla Cloud provides SLA-backed 99.99% uptime with automated failover and geo-redundant backups. Enterprise Cloud provides 99.9% uptime with proactive monitoring and optional replication.

When you delete data, we retain copies for one month to allow for recovery of repositories or project management assets. After that period, data is permanently removed from our systems.
  • Compliance comparison

How does Assembla's SOC 2 compare to GitHub's?

Both Assembla and GitHub hold SOC 2 Type II certification. The difference is what is included at which price point. Assembla includes SOC 2 and GDPR compliance in every plan. GitHub reserves these for Enterprise Cloud at $21/user/month. Read the full comparison
COMPLIANCE FEATURE ASSEMBLA GITHUB
SOC 2 Type II All plans Enterprise only ($21/user/month)
GDPR compliance All plans, EU data residency available Enterprise Cloud only
IP whitelisting Enterprise single-tenant (Git, SVN, Perforce) Enterprise Cloud only
SAML SSO All plans (platform access) Enterprise only
Audit logs Available on request (all plans) Basic (all plans) / API (Enterprise only)
SVN & Perforce support All plans Not supported
Single-tenant hosting Available on all products Enterprise Server (self-managed only)
GitHub is the right choice for open-source collaboration and large developer ecosystems. Assembla is the right choice for cross-functional teams building compliance-sensitive, creative, or complex software that requires more than Git.
  • Compliance comparison

The same security stack.
Every plan. Every customer.

Security is not reserved for enterprise tiers. SOC 2, GDPR, AES-256, SSO, RBAC, and IP allowlisting ship with every Assembla plan. Enterprise Cloud adds single-tenant isolation and custom governance configuration on top.
  • Assembla Cloud
Starter & Growth
  • SOC 2 Type II, GDPR, EU-US Data Privacy Framework (DPF)
  • AES-256 encryption at rest, SSL/TLS in transit
  • SSO, OAuth 2.0, 2FA, SAML 2.0
  • RBAC and branch protection
  • User activity audit reports
  • IP allowlisting
  • Daily automated backups + S3
  • US, EU & APAC hosting regions
  • Perforce Cloud
Managed Helix Core
  • SOC 2 Type II, GDPR, EU-US Data Privacy Framework (DPF)
  • Volume encryption on AWS, SSL via P4 protocol
  • SSO & SAML via Perforce extensions
  • RBAC native within Perforce
  • Comprehensive application-level audit logging
  • IP allowlisting at P4 and AWS SG level
  • Automated backups & monitoring
  • US, EU & APAC hosting regions
  • Enterprise Cloud
Custom Cloud
  • All standard security controls included
  • Single-tenant dedicated infrastructure
  • Security hardened from day one, not left at defaults
  • Custom backup schedule, RTO/RPO planning
  • Custom data residency in any AWS region
  • VPN, network isolation, IAM controls
  • Full security documentation for procurement
  • Premium 24x5 support included
  • Related

Continue exploring Assembla.

  • Git hosting
Git & Git LFS Cloud Hosting
Managed Git with project management built in. No Jira required.
  • Perforce hosting
Perforce Cloud Hosting
Fully managed Helix Core for game studios and large binary workflows.
  • SVN hosting
SVN Cloud Hosting
Managed Subversion with modern collaboration features. SOC 2 certified.

Ready to secure your source code?

Talk to our team about your source code security requirements. We provide full compliance documentation for procurement, answer technical security questions, and scope environments around your governance model.
See how teams like yours use Assembla. Read customer stories

FAQS

Security questions,
answered directly.

Both platforms hold SOC 2 Type II certification. The key difference is availability: Assembla includes SOC 2 and GDPR compliance in every plan. GitHub reserves these controls for Enterprise Cloud at $21/user/month. For teams that need compliance across Git, SVN, and Perforce in a single environment, Assembla is the only option. GitHub does not support SVN or Perforce.

Yes. Assembla holds AICPA SOC 2 Type II certification across all areas of our source code management platform. SOC 2 Type II is an audit conducted over an extended period by a licensed CPA from the AICPA. It assesses the effectiveness of our internal security controls across the security, availability, and confidentiality Trust Services Criteria. Full documentation is available on request for your procurement and legal teams.

Yes. We comply with GDPR data protection principles including consent for data collection, granular access controls, full auditability, and the right to erasure. Customers with EU data residency requirements host their repositories in our Frankfurt, Germany region. All EU personal data is processed in compliance with GDPR. Full GDPR documentation is available on request.

All data stored on Assembla uses AES-256 encryption at rest on AWS infrastructure. Data in transit uses SSL/TLS encryption. Physical security at our data centers in Ohio (US), Frankfurt (Germany), and Mumbai (India) is managed by AWS staff under their shared responsibility model.

Assembla provides RBAC natively across Git, SVN, and Perforce. SVN and Perforce access controls work at the folder, branch, and file level, allowing organizations to restrict specific repositories or assets to individual contractors or teams. Branch protection rules prevent unauthorized merges. IP whitelisting restricts repository access by network. Audit logs are available on request for legal and compliance purposes.

When you delete data on Assembla, we retain copies for one month to allow for recovery of repositories or project management assets. After that period, data is permanently removed. Daily automated backups and S3 bucket support are included in every plan. Enterprise environments support custom backup schedules and retention policies configured to your specific recovery requirements.