Our compliance programme
AscenAi is powered by Ascendum Corporate Advisory LLC, 10124 N McKinley Drive, Kansas City, MO 64157 — phone +1 (267) 806-0149, fax +1 (913) 273-0612 — and is run against the SOC 2 trust services criteria. This page sets out the controls behind each criterion, the evidence we keep, how we test the platform under load, and who to contact.
Where we stand today
The controls described here are implemented and operating. A formal SOC 2 Type II attestation from an independent auditor is in progress; until that report is issued we describe AscenAi as SOC 2 aligned rather than certified, and we will publish the report date here when it completes.
Trust services criteria
- Row-level security on every table, scoped to user, group and corporation
- Super-admin approval required before a new organisation gets books
- Breached-password screening, one-time-code recovery and invite-only membership
- Server functions re-check authorisation; client-side checks are treated as UX only
- Managed cloud hosting with automated daily backups and point-in-time recovery
- Scheduled jobs are bounded and chunked so a slow provider cannot stall the platform
- Health and error monitoring with findings tracked to closure
- Imported bank and card lines land under review; nothing posts without a human decision
- Double-entry validation rejects unbalanced journals at the database layer
- Bulk posting runs in chunks with per-row outcomes, dry-run validation and idempotent resume
- QuickBooks line-by-line reconciliation flags any gap between source statements and books
- TLS 1.2+ in transit, AES-256 at rest, including uploads and backups
- Client groups are isolated; one group's data is never visible while another is open
- Card details are handled by the payment processor and never stored by AscenAi
- Personal data collected only to deliver the engagement, never sold or used for advertising
- Statutory retention honoured; export or deletion on request within 30 days
- Sub-processors limited to hosting, bank aggregation, email delivery and payments
Evidence and continuous testing
Every posting, edit, reversal, import and privileged action writes an immutable audit row with actor, timestamp, scope and before/after values.
Recurring checks look for duplicate ledgers, orphaned journal lines, unbalanced entries, out-of-period postings and bank balances that drift from posted activity.
Report, ledger and tax queries are exercised against production-scale data (180k+ journal entries) with indexes on the journal tables, so balance sheets, P&L and returns return inside interactive time instead of timing out.
Security and monitoring findings are triaged, assigned and closed with a recorded fix, so control failures have a documented remediation path.
10124 N McKinley Drive
Kansas City, MO 64157
United States
Phone: +1 (267) 806-0149
Fax: +1 (913) 273-0612
AscenAi is a brand of Ascendum Corporate Advisory LLC, which is the data controller and the merchant of record for subscriptions.
Security officer: Mehul Shah, CEO
Security reports: security@ascenai.io
Client support: support@ascenai.io
Corporate: corp@ascencorp.com
Phone: +1 (267) 806-0149
Fax: +1 (913) 273-0612
Reports are acknowledged within one business day.
