How Ascen protects your data (security overview)

Last updated: September 21, 2026

Applies to: everyone — workers, partners, and clients.

Summary: Ascen processes sensitive payroll, identity, and financial data, and protects it with encryption in transit and at rest, SOC 2 Type 2-certified controls, annual penetration testing, and strict internal access practices. You also have rights over your personal information — access, correction, and deletion — which you can exercise at any time. Full details: ascen.com/security and ascen.com/privacy.

How your data is protected

From Ascen's published Security policy:

  • Encryption everywhere — all data is encrypted in transit and at rest.

  • SOC 2 Type 2 certified — our controls are independently examined. The report itself is shared under NDA; see below.

  • Hardened infrastructure — hosted on AWS; code and infrastructure changes are reviewed and tested before deployment, with vulnerability scanning built into the development lifecycle.

  • Annual penetration testing — at minimum, by external testers.

  • Authenticated APIs — every API interaction requires authentication.

  • People controls — every Ascen employee passes a background check, completes security-awareness training, and uses company-managed multi-factor authentication and password managers.

  • Bug bounty — security researchers can responsibly disclose vulnerabilities; see ascen.com/security for how to reach the program.

Requesting our SOC 2 Type 2 report

Ascen is SOC 2 Type 2 certified, and we're glad to share the report with partners and clients who need it for their own diligence — under a signed non-disclosure agreement. The report sets out our systems, controls, and internal processes in detail, so it isn't something we publish or send out openly.

To request it, email support@ascen.com. We'll get an NDA in place and send the report once it's signed. If you only need the high-level picture, the summary above and ascen.com/security can be shared freely and answer most security questionnaires.

What you can do on your side

  • Use a strong, unique password and set up two-factor authentication — see How to log in, reset password and 2FA. (For some account types, 2FA is required and can't be disabled.)

  • Be alert to payment-change fraud — Ascen support will never pressure you to urgently reroute your pay. Bank-detail changes go through your portal, not email.

  • Report anything suspicious to support@ascen.com.

Your privacy rights

Per Ascen's Privacy Policy, you have rights over your personal information regardless of where you live — including the right to access a copy of your data, correct inaccurate data, request deletion, object to or restrict certain processing, data portability, and to withdraw consent — without discrimination for exercising them.

To exercise any of these, see Privacy Requests (phone and email channels). One note: as your Employer of Record, Ascen is the controller for your employment, payroll, and tax data, so you can send those requests to us directly at support@ascen.com. For some other data we process as a service provider (processor) on behalf of your staffing Partner or client, we may route your request to them, or you can contact them directly.

Related articles

  • Privacy Requests

  • How to log in, reset password and 2FA

  • Who is my employer of record and who do I contact?