01Security Philosophy
At Starside Technologies, security is not a compliance checklist—it is foundational engineering. The AssembleIT platform is designed to house the world's most sensitive aerospace architectures: launch vehicle telemetry, satellite subsystem designs, flight software requirements, and civil airworthiness compliance records.
We adhere to defense-in-depth principles across the entire hardware, network, application, and human operations stack.
02Core Architecture Pillars
Our infrastructure is designed to provide complete protection against unauthorized access, exfiltration, and operational disruption:
Zero Trust Architecture
Every API request, graph mutation, and telemetry payload is authenticated, authorized, and cryptographically verified at runtime.
Strict Tenant Isolation
Logical and physical boundary protections prevent cross-tenant memory or storage bleed across multi-tenant clusters.
BYOK & Hardware Key Stores
Customer-managed encryption keys (BYOK) with automated HSM envelope encryption and customer-controlled revocation.
Export & ITAR Readiness
Dedicated sovereign regions and air-gapped on-premises deployments built for dual-use defence and aerospace programmes.
Zero Secondary Training
Your proprietary engineering models, CAD telemetry, and requirement graphs are strictly quarantined and never used to train public LLMs.
Cryptographic Audit Logs
Append-only, tamper-evident audit journals recording every parameter change, approval sign-off, and certification trace.
03Cryptography & Key Management
All data stored within or transmitted across Starside systems is protected by modern cryptographic standards:
- Data in Transit: TLS 1.3 enforced across all external and internal microservice communication endpoints, using HSTS and ECDHE key exchanges for Perfect Forward Secrecy.
- Data at Rest: AES-256 encryption applied at the storage, database, and object layer. Keys are managed through FIPS 140-2 Level 3 validated Hardware Security Modules (HSMs).
- Customer-Managed Keys (BYOK): Enterprise customers retain the ability to generate, rotate, and revoke their own encryption root keys via AWS KMS, Azure Key Vault, or HashiCorp Vault.
04Multi-Tenant Segregation
AssembleIT enforces strict boundary isolation between enterprise organizations:
- Logical Database Partitioning: Every database query is executed through tenant-scoped contexts enforced at the ORM and database engine level.
- Dedicated Virtual Private Enclaves: High-tier enterprise workloads run in dedicated VPCs with isolated compute clusters and private peering.
- Air-Gapped / On-Premises Option: For sensitive defense programmes requiring physical isolation, Starside provides fully disconnected, containerized on-premises deployments.
05Compliance & Standards
Our engineering and operational processes align with international aerospace and cybersecurity standards:
- ISO/IEC 27001: Certified information security management system covering software development, infrastructure management, and support.
- SOC 2 Type II: Independently audited against Trust Services Criteria for Security, Availability, and Confidentiality.
- DO-178C & DO-254 Tool Qualification: Deterministic traceability and tool qualification evidence dossiers (TQP/TAS) available for avionics certification programmes.
- ITAR & Export Control Compliance: Strict personnel clearance protocols and dedicated US/EU/India sovereign cloud hosting options.
06Immutable Audit Trails
In aerospace certification, accountability is paramount. AssembleIT automatically records every user action, graph change, requirement modification, and verification execution into an append-only, tamper-evident audit journal.
Audit logs are cryptographically sealed and streamable directly into your organization's Security Information and Event Management (SIEM) system (Splunk, Datadog, or Microsoft Sentinel).
07Resiliency & Disaster Recovery
Starside ensures mission continuity with high-availability multi-zone architecture:
- Recovery Point Objective (RPO): < 5 minutes with continuous transactional log shipping and automated cross-region replication.
- Recovery Time Objective (RTO): < 1 hour with automated failover and container orchestration.
- Daily Automated Backups: Point-in-time recovery archives encrypted and stored in geographically isolated immutable vaults.
08Vulnerability Management & Pen Testing
We maintain an aggressive, continuous testing posture:
- Automated Static (SAST) and Dynamic (DAST) application security scanning in our CI/CD pipelines.
- Continuous software dependency analysis and SBOM generation to eliminate supply chain vulnerabilities.
- Annual third-party black-box and white-box penetration tests conducted by accredited independent cybersecurity firms.
09Responsible Disclosure Program
We value the contributions of security researchers. If you believe you have discovered a vulnerability in our software or systems, please report it responsibly:
- Submit your report directly to ceo@vyomfix.com (or security@starsidetech.com).
- Provide detailed steps to reproduce the issue, including proof of concept code if applicable.
- Allow us reasonable time to investigate and remediate the issue prior to public disclosure.
- Do not access, modify, or destroy customer data during your research.
10Security Team Contact
For security inquiries, audit report requests, or enterprise compliance questionnaires:
Starside Information Security Office
STARSIDE TECHNOLOGIES Pvt. Ltd.
Executive Contact: ceo@vyomfix.com
Headquarters: Bangalore (Bengaluru), Karnataka, India
PGP Key available upon request.
Emergency Security Response: 24/7 Monitoring for Enterprise Customers.