Data Security Plan
Ascendum Corporate Advisory LLC maintains this written information security plan for the Ascen Tax USA portal, aligned to IRS Publication 4557 (Safeguarding Taxpayer Data), the Gramm-Leach-Bliley Act and the FTC Safeguards Rule. It describes the controls that are in place in this application today.
1. Access is limited to who needs it
- Roles are stored separately from user profiles and are granted one at a time by an administrator — there is no self-service escalation.
- Three roles only: administrator, preparer and client. Preparers see the returns assigned to them; clients see only their own file.
- Every table enforces row-level security at the database, so a stolen browser session cannot read another taxpayer's records.
- Administrators can suspend an account instantly; the suspended session is ejected within a minute rather than at next sign-in.
2. Sessions lock themselves
- Automatic sign-out after 15 minutes of inactivity, with a 60-second on-screen warning.
- Hard 8-hour session lifetime regardless of activity.
- Sensitive pages and every server call are sent with no-store cache headers so nothing is retained by shared proxies or a store's browser cache.
3. Taxpayer data is encrypted
- All traffic is HTTPS-only with HSTS preload; insecure requests are upgraded.
- Social Security and taxpayer identification numbers are held in a restricted encrypted vault, not in ordinary application tables, and are never returned to the browser in full.
- Uploaded documents live in private storage; links are short-lived and signed per request.
- Automated document reading masks SSN/EIN values before any text leaves the processing step.
4. Everything is logged and monitored
- An append-only access trail records who touched which taxpayer record, the action, the timestamp, the IP address and the device.
- Role grants and revocations, account suspensions, session locks and consent signatures are all written to the same trail.
- Administrators review the roster — roles, signed agreements, suspension state and last review date — from the Users & access screen.
5. Written consent before anything is processed
- Clients must sign the client agreement, privacy notice, IRC §7216 consent to use and disclose tax return information, the E-SIGN consent and the automated document-reading consent before the portal will open.
- Signatures capture the typed name, agreement version, timestamp, IP address and device.
- IRC §7216 disclosure consent is separate and explicit; tax return information is not used for any purpose outside preparing and filing the return.
6. Browser and transport hardening
- Strict Content-Security-Policy limiting scripts, frames, forms and connections to this site and our payment processor.
- Clickjacking, MIME-sniffing and cross-origin isolation protections enabled on every response.
- Payments are handled entirely by the payment processor's hosted fields; card numbers never touch our servers.
7. Incident response and retention
- If we identify unauthorized access to taxpayer data we will notify affected clients and report to the IRS Stakeholder Liaison and applicable state agencies as required.
- Documents and return records are retained for the period required by federal and state tax rules, then deleted from active systems.
- Clients may request a copy or deletion of their non-required records by contacting the office.
Report a security concern
Contact Mehul Shah at tax@ascentaxus.com or (816) 294-5633. Mailing address: 10124 N McKinley Drive, Kansas City MO 64157.
See also our security architecture, privacy notice and client agreement.