Security, privacy & compliance

Built and hosted in Canada, compliant by design

Your clients' data doesn't leave the country, and every safeguard (from CASL-friendly messaging to role-based access) is built in. Compliance you can stand behind, from a team you can actually reach.

Your own private space

Every business on AscendCRM lives in its own walled-off space. The wall is built into the database itself, not just the screens, so one business can never see another’s data.

Role-based access

Owner, team lead, agent and assistant roles gate what each person can see and do. Permissions are additive and enforced per record.

Per-deal delegation

Delegate a single task on a single file ('upload disclosures here') without exposing commission or offer terms. Scoped, per-record, revocable.

Human-in-the-loop AI

Signals and Autopilot draft and suggest; client-facing sends always wait for your approval. Auto-apply only touches internal logging and stages.

Encryption & two-step sign-in

Post-quantum key exchange in transit, encrypted at rest, TOTP and SMS two-factor authentication on every account, and audit trails on sensitive records.

Your data, portable

Documents live in object storage with versioning and clean export. Cancel anytime and take everything with you. No lock-in.

Legal & compliance

Built to keep you on the right side of the rules

Real estate runs on regulations: anti-spam, privacy, record-keeping. AscendCRM is designed around Canada's, so staying compliant is the default, not a chore.

CASL-friendly messaging

Canada's anti-spam law means you need consent. AscendCRM never sends a client-facing message without your approval, so you're not blasting people who didn't opt in.

Canadian privacy law

Built around PIPEDA and provincial privacy laws: clear purposes, access and deletion on request, and no selling of your (or your customers') personal information.

Data hosted in Canada

Your leads, clients and documents live in the Canadian region of Amazon Web Services (AWS), not shipped off to a US data centre, with clean export whenever you want it.

RECA-ready record-keeping

Versioned documents and audit trails on sensitive records help you keep the paper trail your board and regulator expect.

AscendCRM is a trade name of Ascentsai Inc., a corporation registered in Canada, and your data is stored in Canada. AscendCRM gives you the tools to stay compliant; it isn't a substitute for legal advice. See our Privacy Policy and Terms.

Certifications & audits

Where we actually stand

Independent certification matters, and it's earned, not claimed. Here's exactly what's in place today and what's underway, so you can judge for yourself instead of trusting a badge.

Post-quantum encryption in transit
Live today

Connections use hybrid post-quantum key exchange: X25519MLKEM768, which combines classical X25519 with ML-KEM-768, the algorithm NIST standardised. It protects traffic against being recorded today and decrypted years from now once quantum computers can break RSA and elliptic curve. Your own security team can confirm it in one command: openssl s_client -connect app.ascendcrm.ca:443 -brief. To be straight about the limit: this covers key exchange. Certificates and signatures are still classical here, as they are everywhere, because no public certificate authority issues post-quantum certificates yet.

Canadian data residency
In place

Your data is stored and processed in AWS's Canadian region. This is a fact about how we run, verifiable today, not a certification.

PIPEDA & provincial privacy law
In place

These are laws we operate under, not badges to be awarded. Our privacy practices, access and deletion handling are built around them.

Independent penetration test
Planned before enterprise sale

We run our own security reviews today. A third-party test by a qualified firm is the next step, and we'll share the summary with customers who ask.

SOC 2 Type II
Not yet certified

The controls a SOC 2 examines (tenant isolation, access control, MFA, audit logging, encryption, change management) are already how the product is built. The audit itself needs a licensed CPA firm and an observation window, and we haven't engaged one yet.

ISO 27001
Not yet certified

No engagement underway. For Canadian buyers SOC 2 is the usual request, so that comes first unless customers tell us otherwise.

SOC 1
Not applicable today

SOC 1 covers controls affecting your financial reporting. If your auditors come to rely on our books features, we'll revisit it.

We will never display a certification we haven't earned. If a certification matters for your purchase, tell us and we'll give you our security documentation and a straight answer on timing.

Role matrix

Everyone sees exactly what they should

Two levels of permission (team roles and per-deal hand-offs) so you can share the work without sharing sensitive details.

Owner / adminFull access: billing, users and business settings.
Team leadSees their team's pipelines and performance; assigns work.
AgentOwns their own leads, clients, deals and documents.
AssistantDelegated tasks only, no commission or offer terms.
Ready when you are

Security your business can stand behind

Customers, quotes, invoices, bookings, team, the books: your whole business in one login, instead of seventeen apps. Start free, no card, no catch.