Security
How AscendFi protects operator data.
Operator data is business-sensitive by nature. This page documents AscendFi's security architecture, data handling practices, and disclosure process for enterprise procurement, security reviewers, and IT administrators.
Data Architecture
Logical isolation by design.
All operator data is logically isolated at the account level. Each operator account operates within a dedicated data partition. Cross-tenant data access is prohibited by system architecture — not only by policy.
Operator context data (decisions, signals, assumptions, workstreams) is used solely to provide the Kaelia service to that operator. This data is not shared across accounts, not used to improve foundation model weights, and not accessible to other customers or AscendFi employees under normal operating conditions.
Encryption
AES-256 at rest. TLS 1.3 in transit.
All operator data at rest is encrypted using AES-256. Data in transit between client and server is encrypted using TLS 1.3 as the minimum protocol. Older TLS versions are not accepted.
Encryption keys are managed using industry-standard key management infrastructure. Keys are rotated on a scheduled basis and on-demand in response to security events.
Access Control
Least privilege by default.
Kaelia operates on a least-privilege access model. Engineering and operations staff do not have standing access to operator data. Data access for legitimate support or debugging purposes requires an audited escalation process with time-limited credentials.
All internal access to production systems is logged and subject to regular access review. Access grants are revoked immediately on role change or departure.
Authentication
Multi-factor authentication required.
Multi-factor authentication is enforced for all operator accounts. Session tokens are short-lived and are rotated on each authentication event. Sessions can be remotely invalidated by the operator at any time from the account settings.
AscendFi does not store operator passwords in plaintext or in reversible format. Password hashing follows current industry best practice.
Infrastructure
Enterprise cloud, US-based, multi-AZ.
Kaelia is hosted on enterprise-grade cloud infrastructure located in the United States. Infrastructure is distributed across multiple availability zones to ensure service continuity in the event of a single-zone failure.
AscendFi does not operate physical servers. Infrastructure providers are selected based on security posture, geographic compliance, and operational reliability.
Data Retention
Defined retention with deletion on request.
Operator data is retained for the duration of the active account. Following account closure, data is retained for 90 days to support potential restoration requests and then permanently deleted.
Operators may request earlier deletion of their data by contacting privacy@ascendfiai.com. Deletion requests are processed within 30 days. Operators wishing to retain their own data before closure may export it via the account settings prior to closing.
Incident Response
Structured response with operator notification.
AscendFi maintains a documented incident response process. In the event of a security incident affecting operator data, AscendFi will notify affected operators within 72 hours of confirming the nature and scope of the incident.
Notifications include: what data was affected, the scope of access, actions taken to contain the incident, and recommended actions for affected operators.
Vulnerability Disclosure
Responsible disclosure is welcomed.
Security vulnerabilities can be reported to security@ascendfiai.com. AscendFi commits to acknowledging all reports within 24 hours and to providing status updates throughout the investigation period.
We request that researchers provide reasonable disclosure time before public reporting and that they avoid accessing or modifying operator data during investigation. We do not pursue legal action against researchers acting in good faith.
Enterprise Inquiry
Enterprise procurement teams conducting security reviews may request detailed documentation including infrastructure diagrams, data flow maps, and vendor security posture information.
Contact security@ascendfiai.com with your organization name and the specific documentation required. We aim to respond within one business day.
