Trust & Security

The controls we use to protect your data — and the certifications we're working toward. Last updated May 27, 2026.

Built on SOC 2 aligned principles. We're not yet SOC 2 certified — we're pre-certification. We've adopted controls aligned with the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality) so we're audit-ready when it's time. We won't claim certification we don't have.

How we protect your data

Encryption

Access control

Data minimization & retention

Subprocessors

We use the following third-party services to deliver AscendSync Code. Each is bound by their own published security and privacy commitments.

ProviderPurposeSecurity posture
ReplitHosting, application database, identity providerSOC 2 Type II
OpenAIGPT-5.6 Sol, Terra, Luna, voice transcriptionSOC 2 Type II, CSA STAR Level 1
AnthropicClaude Sonnet 5, Claude Opus 4.8, Claude Fable 5SOC 2 Type II, ISO 27001
GoogleGemini 3.1 ProSOC 1/2/3, ISO 27001/27017/27018, FedRAMP High
OpenRouterMulti-model gateway (Mistral, Llama, DeepSeek, Grok)Forwards to upstream providers; see their privacy policy

AI training

We have not opted in to any model-training program. Per their published API policies, OpenAI, Anthropic, and Google do not train their models on data submitted via their paid API endpoints. OpenRouter-routed models follow each upstream provider's training policy.

Operational security

Vulnerability management

Backups & resilience

Incident response

Reporting a vulnerability

If you discover a security issue, please email [email protected]. Please do not publicly disclose until we've had a chance to remediate. We aim to acknowledge reports within one business day.

Compliance posture

We maintain a written controls inventory mapped to the SOC 2 Trust Services Criteria. We're happy to share our self-assessment with prospective enterprise customers under NDA.

GDPR alignment

We apply the principles of the EU General Data Protection Regulation (GDPR) — lawful basis, data minimization, purpose limitation, retention limits, and the full set of user rights (access, rectification, erasure, portability, restriction, objection) — for every user regardless of location. We do not claim full legal GDPR compliance and we do not currently offer a signed Data Processing Agreement off the shelf. Enterprise customers needing a DPA should contact [email protected]. See our Privacy Policy for the full user-rights workflow.

Compliance roadmap

Frequently asked questions

Is AscendSync Code SOC 2 certified?

Not yet. We are pre-certification and have adopted controls aligned with the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality) so we are audit-ready. We will not claim a certification we do not hold.

Is AscendSync Code GDPR compliant?

We apply GDPR principles — lawful basis, data minimization, retention limits, and the full set of user rights (access, rectification, erasure, portability, restriction, objection) — for every user regardless of location. We do not claim full legal GDPR compliance; please contact [email protected] for a Data Processing Agreement if you require one.

Do you train AI models on my data?

No. We have not opted in to any model-training program. OpenAI, Anthropic, and Google have publicly stated that data submitted via their paid API endpoints is not used to train their models.

Where is my data stored?

Application data is stored in a Replit-managed PostgreSQL database with encryption at rest (AES-256). Uploaded files are stored in private object storage and automatically deleted according to file type: audio within 24 hours, documents and images within 30 days, and video is never stored — it is transcribed and immediately discarded.

How do I report a security vulnerability?

Email [email protected]. We acknowledge critical reports within one business day and follow the Coordinated Vulnerability Disclosure model. See /.well-known/security.txt for machine-readable contact details.

How do I delete my account or export my data?

Email [email protected]. We respond to deletion and export requests within 30 days. Self-service versions are on our roadmap.