Built to be audited
AscenAi carries client financial records, so it is engineered against the SOC 1 (controls over financial reporting) and SOC 2 (security, availability, confidentiality and privacy) trust criteria.
All traffic is TLS 1.2+ end to end. Data at rest, including database storage, file uploads and backups, is encrypted with AES-256 by the hosting platform.
Every table is protected by row-level security tied to the signed-in user, their group and their corporation. A user physically cannot query another client group's ledgers.
Email and password with breached-password screening, one-time-code recovery, Google sign-in, invite-only membership and super-admin approval for new organisations.
AI never posts silently. Imported and suggested entries sit under review until a human approves them — the control an SOC 1 auditor looks for over financial reporting.
Postings, edits, deletions, scope switches, bank refreshes, screen-share sessions and admin actions are all written to immutable audit logs with user, timestamp and before/after values.
Group isolation is enforced in the database, not the interface. While one client group is open, nothing from another group can be read, exported or reported on.
Managed Postgres with point-in-time recovery and automated daily backups. Book seals and period freezes stop closed years from being altered.
Automated dependency scanning, database security linting, error monitoring and periodic access reviews of every membership and role.
How our controls map to SOC 1 and SOC 2
SOC 1 covers controls relevant to your financial reporting; SOC 2 covers how we run the platform. The table below is the control narrative we work to and the evidence we can produce for your auditor today.
| Control area | SOC 1 — financial reporting | SOC 2 — trust services |
|---|---|---|
| Change management | Every posting change is journalised and traceable to an approver. | Application changes are versioned, reviewed and released through an audited pipeline. |
| Logical access | Roles map to accounting duties — clerk, accountant, group admin, viewer. | Row-level security, invite-only onboarding and periodic access review. |
| Completeness and accuracy | Bank feed to ledger reconciliation, QuickBooks line-to-line matching and balance verification. | Integrity checks, duplicate detection and error monitoring. |
| Confidentiality | Client groups are segregated in the database layer. | Encryption in transit and at rest; secrets held in a managed secret store. |
| Availability | Period seals protect reported figures. | Managed hosting, automated backups and point-in-time recovery. |
Formal SOC 1 Type II and SOC 2 Type II attestation reports are issued by an independent CPA firm. Ask us for the current status of our examination and, where a report is available, we will share it under NDA.
Data privacy
We never sell client data, never use your ledgers to train third-party models, and never share records outside your group without written instruction.
We collect what the books need. Card numbers are never stored by AscenAi — payments run through our PCI-DSS Level 1 processor.
Records are retained for the statutory period you require. On request we export your books and delete the workspace, including backups, on the published schedule.
Security contact: security@ascenai.io. Report a suspected vulnerability there and we will acknowledge within one business day.
