Compliance

Our compliance programme

AscenAi is powered by Ascendum Corporate Advisory LLC, 10124 N McKinley Drive, Kansas City, MO 64157 — phone +1 (267) 806-0149, fax +1 (913) 273-0612 — and is run against the SOC 2 trust services criteria. This page sets out the controls behind each criterion, the evidence we keep, how we test the platform under load, and who to contact.

Where we stand today

The controls described here are implemented and operating. A formal SOC 2 Type II attestation from an independent auditor is in progress; until that report is issued we describe AscenAi as SOC 2 aligned rather than certified, and we will publish the report date here when it completes.

Trust services criteria

Security (common criteria)
  • Row-level security on every table, scoped to user, group and corporation
  • Super-admin approval required before a new organisation gets books
  • Breached-password screening, one-time-code recovery and invite-only membership
  • Server functions re-check authorisation; client-side checks are treated as UX only
Availability
  • Managed cloud hosting with automated daily backups and point-in-time recovery
  • Scheduled jobs are bounded and chunked so a slow provider cannot stall the platform
  • Health and error monitoring with findings tracked to closure
Processing integrity
  • Imported bank and card lines land under review; nothing posts without a human decision
  • Double-entry validation rejects unbalanced journals at the database layer
  • Bulk posting runs in chunks with per-row outcomes, dry-run validation and idempotent resume
  • QuickBooks line-by-line reconciliation flags any gap between source statements and books
Confidentiality
  • TLS 1.2+ in transit, AES-256 at rest, including uploads and backups
  • Client groups are isolated; one group's data is never visible while another is open
  • Card details are handled by the payment processor and never stored by AscenAi
Privacy
  • Personal data collected only to deliver the engagement, never sold or used for advertising
  • Statutory retention honoured; export or deletion on request within 30 days
  • Sub-processors limited to hosting, bank aggregation, email delivery and payments

Evidence and continuous testing

Audit trails

Every posting, edit, reversal, import and privileged action writes an immutable audit row with actor, timestamp, scope and before/after values.

Data integrity checks

Recurring checks look for duplicate ledgers, orphaned journal lines, unbalanced entries, out-of-period postings and bank balances that drift from posted activity.

Load and performance testing

Report, ledger and tax queries are exercised against production-scale data (180k+ journal entries) with indexes on the journal tables, so balance sheets, P&L and returns return inside interactive time instead of timing out.

Findings management

Security and monitoring findings are triaged, assigned and closed with a recorded fix, so control failures have a documented remediation path.

Legal entity and address
Ascendum Corporate Advisory LLC
10124 N McKinley Drive
Kansas City, MO 64157
United States
Phone: +1 (267) 806-0149
Fax: +1 (913) 273-0612

AscenAi is a brand of Ascendum Corporate Advisory LLC, which is the data controller and the merchant of record for subscriptions.

Contact the compliance team

Security officer: Mehul Shah, CEO

Security reports: security@ascenai.io

Client support: support@ascenai.io

Corporate: corp@ascencorp.com

Phone: +1 (267) 806-0149

Fax: +1 (913) 273-0612

Reports are acknowledged within one business day.