Trust Center

Your data, your legacy — protected.

This page is maintained by Ascendra to answer common security and privacy questions. It describes the platform controls we operate and the practices we commit to. It is not a certification, and it does not replace your own review of the linked policies.

Row-Level Security everywhere

Every user-owned table enforces Row-Level Security, so account, budget, transaction, and goal data is scoped to its owner at the database layer.

Encrypted institution tokens

Access tokens for connected institutions are encrypted with AES-256-GCM before storage and only decrypted inside authenticated server functions.

Least-privilege server

App logic runs through typed server functions that validate a bearer token on every call. Admin credentials are never shipped to the browser.

Full data portability

You can download every row we store about you, delete AI history, clear transactions, disconnect institutions, and delete your account from Settings → Privacy.

Policies & disclosures

Shared responsibility: Ascendra operates the platform controls above; you are responsible for keeping your login credentials safe and for the accuracy of data you enter. Ascendra is not a bank, brokerage, or registered investment adviser. Content is educational and is not personalized investment, tax, legal, or credit advice.