Last updated: 26 July 2026
Data security
1. Our commitment
Protecting our members' information is one of ASCA's highest priorities. We apply a layered security approach designed to safeguard customer data, financial information and digital services across our technology, operations and internal processes.
2. Encryption
All data transmitted between your device and our systems is protected using industry-standard encryption protocols, including Transport Layer Security (TLS). Sensitive information is encrypted both in transit and at rest using strong cryptographic standards.
3. Access controls
Access to customer information is granted strictly on a need-to-know basis through role-based access controls and is further protected by multi-factor authentication, continuous monitoring and comprehensive audit logging.
4. Secure by design
Our security framework follows the principles of least privilege, defence in depth and secure-by-design. Security controls are integrated throughout the development lifecycle and are supported by continuous vulnerability management, regular security testing and ongoing monitoring to help identify and respond to potential threats.
5. Ongoing improvement
We continuously review and strengthen our security controls to address evolving cyber threats, emerging technologies and changes in the regulatory landscape. Our security programme includes preventative, detective and responsive measures designed to maintain the confidentiality, integrity and availability of customer information, including incident-response and business-continuity procedures.
6. Your role in staying secure
ASCA will never ask you to disclose your password, one-time verification codes, PIN, recovery phrase, seed phrase or private cryptographic keys.
If you receive any communication claiming to be from ASCA requesting this type of information, do not respond, do not click any links and do not share any information. Please report the communication immediately and contact us through our official support channels at legal@asca.capital.
7. Reporting a vulnerability
If you believe you have found a security vulnerability affecting ASCA, please report it responsibly to legal@asca.capital so our security team can investigate.