Legal
Security Contact
Last updated September 2026
We appreciate coordinated disclosure. To report a suspected vulnerability, email security@ascendrawealth.com with reproduction details.
What we ask
- Give us reasonable time to remediate before public disclosure.
- Avoid accessing data that isn't yours or degrading the Service.
- Do not run automated scanners against production without written approval.
What we practice
- Row-Level Security on every user-owned table.
- AES-256-GCM encryption for Plaid access tokens at rest.
- Least-privilege server functions with bearer-token validation.
- HTTPS end-to-end and short-lived session tokens.
Ascendra is an educational financial wellness platform — not a bank, brokerage, or registered investment adviser. Content is for general education and is not personalized investment, tax, legal, or credit advice.