Vascendascend
Sign inGet started
Home

Legal

Security

How we protect data, infrastructure, and access, how we respond to incidents, and how to report a vulnerability.

Last updated: 12 August 2026

1. Our approach

Vascend handles accounting documents, bank transactions, and source code: data whose compromise would cause direct, concrete harm. Security is therefore a design requirement, not a layer added afterwards. We apply three operating principles: least privilege on every access, defence in depth at every perimeter, and assumed compromise when designing controls.

2. Encryption

Data is encrypted in transit with TLS 1.3 (TLS 1.2 as the minimum accepted) and at rest with AES-256. User credentials are stored as hashes using algorithms designed to resist large-scale computation. Application secrets do not live in the codebase: they are held in a dedicated store, rotated periodically, with access logged.

3. Access control

Access to the platform is protected by authentication with expiring sessions and immediate revocation. Two-factor authentication and SSO provider sign-in are available. Permissions follow a role model: each role exposes only the operations its function requires. Administrative access to infrastructure requires multi-factor authentication, travels over private networks, and is fully logged.

4. Infrastructure

Services are isolated in containers and exposed only through a gateway that applies authentication, rate limiting, and application traffic filtering. Databases are not reachable from the public network. Communication between internal services runs over a private network. Components are updated on a defined cycle, with critical security patches applied as a priority. Primary infrastructure sits in European Union data centres holding physical and environmental security certifications.

5. Secure development

Every code change is reviewed before it is merged. The pipeline runs static analysis, dependency checks, and secret scanning; a critical finding blocks the release. Development and production environments are separated and share no credentials. Real data is not used in test environments.

6. Monitoring and incident response

We collect application, access, and network logs in a central system, with alerts on anomalous patterns: repeated sign-in attempts, error spikes, irregular API traffic. In the event of an incident we follow a defined procedure: containment, impact assessment, restoration, root cause analysis. Where an incident involves a personal data breach posing a risk to data subjects, we notify the supervisory authority within seventy-two hours of becoming aware of it and inform affected customers without undue delay.

7. Continuity and backups

Data is backed up automatically and encrypted, retained across multiple days, with periodic restore testing: an unverified backup is not a backup. We maintain defined recovery time and recovery point objectives, reviewed as the architecture changes, and documented procedures for restoring critical services.

8. Responsible disclosure

If you find a vulnerability, write to security@vascend.it with a technical description and steps to reproduce. We respond within three working days and keep you updated until the issue is closed. We ask that you do not disclose the vulnerability before it is fixed, do not access other users' data, and do not degrade the availability of the Service while investigating. On those terms we take no legal action against good-faith reporters. Active security testing against the infrastructure requires prior written authorisation.
Data UseCookie Policy
ascend
GitHubJoin Discord ↗X [Twitter]Let’s talk
Vascend HorizonVascend Talos
LegalPrivacyCookieData useSecurity
© 2026 Vascend Technologies · VAT IT04911550616Back to top ↑