Security
Security & Trust
Your clients' data is your livelihood. Here's how we protect it.
Encryption & Authentication
- All traffic to AscendHub is encrypted in transit over HTTPS (TLS)
- Data at rest is encrypted by our managed cloud platform
- Sign-in is handled by our platform provider — passwords are hashed, never stored by us in readable form
- Google sign-in and email one-time codes are supported; API access always requires an authenticated token
Access Control & Isolation
- Every account is provisioned its own isolated workspace — records are scoped to your workspace and never shared across accounts
- Row-level security is enforced on the server for leads, clients, policies, commissions, applications and documents
- Team plans support admin and agent roles, including restricting who can view commission data
- Public links (lead intake forms and application signing links) are limited to a single record and carry no access to the rest of your data
Hosting & Reliability
- AscendHub runs on managed cloud infrastructure operated by our platform provider, which handles patching and platform-level backups
- We do not currently publish an uptime SLA — planned and unplanned downtime is communicated in-app
- Payments are processed by Stripe; card numbers never touch our systems or database
- Calls and text messages are carried by Twilio, and transactional email by Resend
Your Data & Retention
- We never sell your data, and we do not use your client records to train AI models
- Export your book to CSV at any time from Settings
- Delete your account from your Profile page — your data is removed within 30 days except where retention is required by law
- Admins on team plans can set retention rules that automatically purge older activity history, audit logs and notifications
Compliance & Honest Limits
- We do not claim SOC 2, ISO 27001 or PCI certification — Stripe handles card data under its own PCI compliance
- AscendHub is not a HIPAA-covered platform and should not be used to store protected health information
- You remain responsible for TCPA and state consent requirements when calling or texting through the app
- Security questions or a suspected incident? Reach us through the in-app support agent and we will respond directly
