Assembly Studio

Secure by design

Build as fast as you want. Authentication, permissions, and encryption are platform infrastructure, engineered, audited, and on by default.

SOC 2SOC 2 Type II
HIPAAHIPAA
GDPRGDPR
CCPACCPA

What makes Assembly Studio different

Apps you build inherit our platform's security model, so you don't wire it up yourself.

  • Clients sign in with magic links, Google, or a password. You control which methods are allowed, and MFA can be enforced on top. Login is platform infrastructure, so no app generates its own.

  • Who sees what is decided by Assembly's contact and company model. Clients see only their own data, and apps can be limited to specific clients.

  • Each app runs in its own sandboxed environment with its own database, scoped to your workspace. An issue in one app can't reach another, or anyone else's data.

  • When an app needs a third-party service, you provide the key through a secure form and the platform stores it. Credentials are injected at runtime, never hardcoded into what the AI generates.

Metta HealthPatient care

How Metta Health scales HIPAA-compliant patient authorizations with Assembly

50+

HIPAA-compliant workflows

80%

cost savings

5x

ROI vs. alternative vendors

Read firm’s story

Frequently asked questions

The security-critical parts of every app aren't written by AI — they're built into Assembly's maintained foundation and enforced at build time. Apps never implement their own authentication: every request runs on short-lived, cryptographically signed tokens scoped to that specific app, and a token minted for one app is rejected by every other. Each app gets its own dedicated database, and access to workspace data is validated server-side on every request — isolation is enforced at the storage layer, not by generated code remembering to filter.

Secrets and API credentials are server-only by construction: injected as environment variables at deploy, encrypted at rest, and never returned through any API. If generated code tries to pull a secret into the browser, the build fails — the app won't ship.

Your customer data is stored on enterprise cloud infrastructure in the United States, encrypted in transit (TLS) and at rest (AES-256). Each app you build gets its own dedicated database, scoped to your workspace. Details on hosting providers and regions are in the Assembly Trust Center.

No, Assembly never uses your workspace data or your clients' data to train any AI models, whether by Assembly or by our AI providers. Builds run in isolated environments, and the AI's access ends when the build does.

Every app is born with its own boundaries: a dedicated codebase, its own database, and its own deployment, all scoped to your workspace. Apps render in sandboxed environments inside the platform and reach data only through Assembly's permission-checked APIs. An issue in one app can't reach another, and can never reach another customer's data.

Assembly uses a small set of vetted subprocessors for cloud hosting, app deployment, AI model inference, payments, and analytics — each bound by data processing agreements. The current, complete list is maintained in the Trust Center and updated whenever it changes.

Secrets and API credentials are never written into generated code. When an app needs a third-party service, you provide the credential through a secure form; the platform stores it encrypted and injects it at runtime as an environment variable. The AI never holds your keys, and they never appear in your app's codebase.

Yes. The Assembly platform is SOC 2 Type II certified and monitored continuously via Secureframe. Because Assembly apps run entirely on this infrastructure — auth, permissions, hosting, and data included — they never leave the audited environment. Reports are available in the Trust Center.

Yes. Assembly supports HIPAA compliance, with a BAA available on the Advanced plan. One boundary applies: AI features aren't covered.

In practice, ready-made apps like secure messaging, file sharing, and contracts can all handle PHI — as long as the app doesn't use AI itself (these are clearly labeled). Building new apps with the app builder isn't covered, since the build process uses AI.

If you're a covered entity, talk to us and we'll map what fits where.

Assembly maintains a documented incident response process: incidents are triaged by severity, contained, and remediated, and affected customers are notified in line with contractual and legal requirements. Because security is engineered at the platform level, a fix ships platform-wide — every workspace and every app at once, with nothing for you to patch.

Other tools generate your app's security along with your app, then hand you scanners to find what the AI got wrong. On Assembly, apps don't generate that layer at all. Authentication, permissions, data scoping, and hosting are platform infrastructure, engineered once and inherited by every app you build. And your apps ship into the client experience your customers already log into, not to a standalone app you have to secure yourself.

Build fearlessly

Every workspace and every app you build inherits the platform's security from day one. See how in our Trust Center.