
San Jose, California, 5 August 2026: Asato, the agentic AI-powered IT asset optimization platform, today announced it has officially achieved HITRUST e1 Certification, marking a significant milestone in the company's ongoing security and compliance journey.
The HITRUST e1 Certification is an independently validated assessment covering 44 essential cybersecurity controls that ensure continuous alignment with the latest threat intelligence and evolving standards across NIST, ISO, and OWASP. Unlike self-attestation questionnaires, the HITRUST AssuranceProgram require validation by an external assessor, giving customers and partners verified, third-party proof, rather than a self-reported claim, that an organization follows foundational security and privacy practices.
This achievement demonstrates Asato's continued commitment to maintaining the highest standards of information security, privacy, and regulatory compliance. This also strengthens the trust its customers and partners place in the company, particularly those in regulated industries such as healthcare and financial services, where data protection and audit-readiness are business-critical.
“Earning HITRUST Certification reflects Asato’s proactive approach to cybersecurity and trust. It also demonstrates the organization’s commitment to managing information risk and protecting sensitive data through a rigorous, proven assurance process.”
– Gregory Webb, CEO, HITRUST.
"HITRUST e1 Certification is an important validation of the security foundation we've built at Asato," said Sundari Mitra, CEO of Asato."Our customers trust us with visibility into their most sensitive IT andAI asset data, and that trust has to be earned continuously. This certification reflects the discipline our teams bring to protecting that data every day, and it's a milestone we're proud to build on as we pursue even higher levels of assurance."
Asato’s HITRUST certification covers critical elements of Information protection, Vulnerability Management, Access Control, Audit Logging andMonitoring, Incident Management, Business Continuity and Disaster Recovery,Risk Management and Data Protection and Privacy, among others.