Your business runs on this data. We treat it that way.
AspirePro holds your clients, projects, tickets, and billing — so security isn’t a feature tier or an enterprise add-on. Every organization on every plan gets the same architecture, described plainly below.
A dedicated database per customer
Every organization runs in its own isolated PostgreSQL database — not a shared table with a customer-id column. Your data is physically separated from every other customer’s, which removes the whole class of cross-tenant leakage bugs by architecture rather than by query discipline.
Encryption in transit and at rest
All traffic is served over TLS (HTTPS), application-to-database connections require SSL, and backups are stored in Amazon S3, where objects are encrypted at rest. Passwords are hashed with bcrypt; API tokens are stored hashed.
Cloudflare WAF & edge protection
The platform sits behind Cloudflare’s Web Application Firewall and global network — DDoS mitigation, bot filtering, and managed WAF rules screen traffic before it ever reaches our servers. Public forms are additionally protected by Cloudflare Turnstile.
Passkeys and two-factor authentication
Every user can sign in with a passkey — Face ID, Touch ID, Windows Hello or a hardware security key — which is phishing-resistant and two-factor by design, with the private key never leaving the device. TOTP two-factor authentication is available to everyone, and organization admins can require it for their entire organization. Access to our own platform administration requires mandatory TOTP MFA — no exceptions.
Granular, role-based access control
Permissions are enforced server-side on every request, down to individual capabilities (who can close a ticket, see billing rates, or export payroll). Client-portal users run under a separate default-deny permission model — clients see only what you explicitly grant.
Automatic nightly backups
Every customer database is backed up nightly to Amazon S3 with 30 days of retention. Backup credentials are write-only — a compromised upload key cannot read or delete existing backups — and restores are tested via the same tooling we run in production.
Payments handled by Stripe
Subscription payments run entirely on Stripe’s PCI-DSS Level 1 infrastructure — hosted checkout and a hosted billing portal. Card numbers never touch, and are never stored on, AspirePro servers.
Audit trails & monitoring
Organization activity is captured in an audit trail on every company, contact, deal and ticket, and our own administrative actions are written to an append-only platform audit log. Errors and anomalies are monitored continuously with alerting on failures.
Hardened, managed infrastructure
Production runs on managed cloud infrastructure with locked-down SSH access, secure cookies, strict session isolation per organization, and separation between the application, admin, and customer domains.
AI that works under your rules
AI in AspirePro is powerful on purpose — and bounded on purpose. Whether it’s our built-in assistant or an AI tool you bring yourself, it can do everything a human can do in your organization, and nothing more: every action runs under the invoking user’s own roles and permissions.
Your data stays yours
You own the content you put into AspirePro — full stop. We process it only to run the service, under your instructions. We don’t sell it, we don’t mine it for advertising, and AI features only process your data when someone on your team invokes them. Cancelling doesn’t delete your organization, and you can request a full export or deletion at any time.
Found a vulnerability?
We welcome good-faith security research. If you believe you’ve found a vulnerability in AspirePro, email support@aspirepro.io with the details and we’ll respond promptly. Please give us a reasonable window to fix the issue before any public disclosure, and don’t access data that isn’t yours while testing.
AI that works under your rules
Prox, our built-in assistant
Prox is powered by xAI’s Grok models over the API, and only processes organization data when someone on your team invokes it. Under xAI’s enterprise API terms, content sent for processing is not used to train their models.
Your permissions, enforced on AI
AI never gets its own privileges. It reads only what the invoking user could see on screen, writes only what they could change themselves, and changes are confirmation-gated. A user’s AI is exactly as powerful — and exactly as limited — as that user.
Bring your own AI (MCP)
Every organization ships with a built-in MCP (Model Context Protocol) server, so your team can connect the AI tool it already uses. Connections authenticate with scoped tokens and operate under the connecting user’s permissions; what your chosen AI provider does with the data is governed by your agreement with them.
Bring your whole services business together
Stop stitching together five tools. Run sales, delivery, support, and billing from one organization — with an AI assistant on every page.