asendia.ai

B+
Trust rating
Good · 88/100
Procurement snapshot
0 critical findings identified — these point to architectural gaps, not just configuration tweaks.
Strengths
SOC 2 Type II
ISO 27001
GDPR
CCPA
Questions to ask
Confirm MTA-STS rollout plans for inbound email
Sign in to see 2 more
Estimated remediation effort: 1–2 days
Based on a passive external scan — supplement with vendor-provided attestations, not a replacement.
Trust Score Trend
→ No change 1 scan · Last scanned March 29, 2026
Your rating Industry average
Score
100 75 50 25 0
B+
asendia.ai
88/100
Compliance & Certifications
5 of 5 verified via Trust Center
SOC 2 TYPE II
SOC 2 Type II
Listed on self-hosted Trust Center
View trust center
ISO 27001
ISO 27001
Listed on self-hosted Trust Center
View trust center
GDPR
GDPR
Listed on self-hosted Trust Center
View trust center
CCPA
CCPA
Listed on self-hosted Trust Center
View trust center
HIPAA
HIPAA
Listed on self-hosted Trust Center
View trust center
Incident History
None in 12 months
March 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
April 2023 – Feb 2026
ChatGPT data exposure
1 source
Resolved
Pro subscribers only
Security Posture
6 items need attention
9 passed
Turn on HSTS (forces browsers to always use HTTPS)
HSTS Header
< 1 hour

This puts visitor logins and session data at risk of interception on untrusted networks. asendia.ai doesn't send the HSTS header, so a browser can still be tricked into connecting over plain, unencrypted HTTP instead of HTTPS — an attacker on the same network (e.g. public wifi) can exploit that gap to intercept traffic. Turning HSTS on tells every browser "always use HTTPS for this site, no exceptions."

PCI-DSS 4.0Req 6.4.1
Required application security controls
NIST 800-53SC-8
Transmission confidentiality and integrity
How to fix this
1Add this response header to your site. If you manage your own server (nginx, Apache, IIS) or a CDN like Cloudflare, add it in that config. If your site is on a managed platform (Wix, Squarespace, Shopify, WordPress.com), search their help center for "custom headers" or ask their support — most support it, though a few don't.
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
2Before adding it, make sure every subdomain (not just the main site) also works over HTTPS — HSTS applies site-wide.
3Confirm it's live: search "http header checker" and enter asendia.ai.
4Once confirmed, submit the domain at hstspreload.org so browsers enforce HTTPS even on a user's very first visit.
Report unlocked.
View all 9 passed checks
DMARC / Email Security
TLS Configuration
Known Breaches
Security Headers
Cookie Security
CVE Exposure
TLS Protocol Support
Certificate Hygiene
Subprocessors & Tech Stack
Company Signals
Claim profile →
Operational risk
Low
11 yrs operating. Well-funded
Lynxradar · Composite signal
Last funding
$40B
Series F · Mar 2025 · SoftBank-led
Crunchbase ↗
Employees
~3,000
+40% YoY growth
LinkedIn ↗
Trust Resources
Claim profile →
Self-hosted Trust Center
asendia.ai/security
Security page
asendia.ai/security ↗
Privacy Policy
asendia.ai/privacy ↗
DPA (Data Processing Agreement)
asendia.ai/dpa ↗
Updated recently
Subprocessors List
asendia.ai/policies/subprocessors ↗
Similar companies in B2B SaaS / Software
Appears in
Claim profile →
SOC 2 Type II certified vendors
847 companies · Updated weekly by LynxRadar
Track
ISO 27001 certified SaaS
312 companies · Updated weekly by LynxRadar
Track
Top AI vendors by trust score
94 companies · LynxRadar ranking
Track
Enterprise-ready SaaS · Trust score A or above
203 companies · LynxRadar ranking
Track