Legal

Security Contact

Last updated September 2026

We appreciate coordinated disclosure. To report a suspected vulnerability, email security@ascendrawealth.com with reproduction details.

What we ask

  • Give us reasonable time to remediate before public disclosure.
  • Avoid accessing data that isn't yours or degrading the Service.
  • Do not run automated scanners against production without written approval.

What we practice

  • Row-Level Security on every user-owned table.
  • AES-256-GCM encryption for Plaid access tokens at rest.
  • Least-privilege server functions with bearer-token validation.
  • HTTPS end-to-end and short-lived session tokens.

Ascendra is an educational financial wellness platform — not a bank, brokerage, or registered investment adviser. Content is for general education and is not personalized investment, tax, legal, or credit advice.