Beta testing — test data only. Do not enter real personal or tax information.

Data Security Plan

Ascendum Corporate Advisory LLC maintains this written information security plan for the Ascen Tax USA portal, aligned to IRS Publication 4557 (Safeguarding Taxpayer Data), the Gramm-Leach-Bliley Act and the FTC Safeguards Rule. It describes the controls that are in place in this application today.

1. Access is limited to who needs it

  • Roles are stored separately from user profiles and are granted one at a time by an administrator — there is no self-service escalation.
  • Three roles only: administrator, preparer and client. Preparers see the returns assigned to them; clients see only their own file.
  • Every table enforces row-level security at the database, so a stolen browser session cannot read another taxpayer's records.
  • Administrators can suspend an account instantly; the suspended session is ejected within a minute rather than at next sign-in.

2. Sessions lock themselves

  • Automatic sign-out after 15 minutes of inactivity, with a 60-second on-screen warning.
  • Hard 8-hour session lifetime regardless of activity.
  • Sensitive pages and every server call are sent with no-store cache headers so nothing is retained by shared proxies or a store's browser cache.

3. Taxpayer data is encrypted

  • All traffic is HTTPS-only with HSTS preload; insecure requests are upgraded.
  • Social Security and taxpayer identification numbers are held in a restricted encrypted vault, not in ordinary application tables, and are never returned to the browser in full.
  • Uploaded documents live in private storage; links are short-lived and signed per request.
  • Automated document reading masks SSN/EIN values before any text leaves the processing step.

4. Everything is logged and monitored

  • An append-only access trail records who touched which taxpayer record, the action, the timestamp, the IP address and the device.
  • Role grants and revocations, account suspensions, session locks and consent signatures are all written to the same trail.
  • Administrators review the roster — roles, signed agreements, suspension state and last review date — from the Users & access screen.

5. Written consent before anything is processed

  • Clients must sign the client agreement, privacy notice, IRC §7216 consent to use and disclose tax return information, the E-SIGN consent and the automated document-reading consent before the portal will open.
  • Signatures capture the typed name, agreement version, timestamp, IP address and device.
  • IRC §7216 disclosure consent is separate and explicit; tax return information is not used for any purpose outside preparing and filing the return.

6. Browser and transport hardening

  • Strict Content-Security-Policy limiting scripts, frames, forms and connections to this site and our payment processor.
  • Clickjacking, MIME-sniffing and cross-origin isolation protections enabled on every response.
  • Payments are handled entirely by the payment processor's hosted fields; card numbers never touch our servers.

7. Incident response and retention

  • If we identify unauthorized access to taxpayer data we will notify affected clients and report to the IRS Stakeholder Liaison and applicable state agencies as required.
  • Documents and return records are retained for the period required by federal and state tax rules, then deleted from active systems.
  • Clients may request a copy or deletion of their non-required records by contacting the office.

Report a security concern

Contact Mehul Shah at tax@ascentaxus.com or (816) 294-5633. Mailing address: 10124 N McKinley Drive, Kansas City MO 64157.

See also our security architecture, privacy notice and client agreement.