Skip to content
01 · Security, compliance & data

For the people who have to sign off.

Regulatory standing, entity structure, data handling, and controls. Where we don't yet have a document to hand you, this page says so rather than implying we do.

Request the diligence packet
Community reinvestment reporting hub header with programme evidence
Evidence-based reporting — demo environment. (Sample data)
02 · Regulatory standing

Who is registered, and for what.

The Zillennial Advisors LLC is an SEC-registered investment adviser, CRD #324808, SEC File No. 801-133744. It delivers investment advice through the Parity platform. Registration does not imply a certain level of skill or training.

Wealth Academy LLC operates the Wealth Academy education platform. It is not an investment adviser and does not provide investment advice.

03 · Entity and responsibility map

Who you'd be contracting with.

The Zillennial Advisors Inc.
Parent company. Employs personnel, operates this website. Not a registered adviser.
The Zillennial Advisors LLC
The SEC-registered investment adviser. Operates Parity. Any individual advisory relationship is with this entity, executed by the individual through the platform.
Wealth Academy LLC
Operates the Wealth Academy education platform.

The signing entity varies by service: advisory services are provided by The Zillennial Advisors LLC; educational programs are delivered by Wealth Academy LLC. Which entity signs depends on the services in scope.

Entity structure

The Zillennial Advisors Inc.

Parent company · operates this website

The Zillennial Advisors LLC

SEC-registered investment adviser. CRD #324808 · SEC File No. 801-133744. Delivers advice through the Parity platform.

Advice

Wealth Academy LLC

Operates the Wealth Academy education platform. Does not provide investment advice.

Education

04 · Data handling

What we collect and what we do with it.

We do not sell data.

What is collected, and only ever voluntarily

Account basics: name, email, date of birth. Financial profile: income, expenses, goals, risk tolerance. If Plaid is linked, which is optional: balances and transaction history. Plus platform usage metrics. Every field beyond name and email is optional.

What Parity never does

Never sees or stores bank login credentials. Never shares personal information with other entities. Does not collect Social Security numbers or government IDs outside optional investing KYC. Never uses your data to train AI models.

Account aggregation

Accounts link through Plaid; users log in directly with their bank. Credentials are never seen or stored by ZA. Plaid is SOC 2 Type II certified — that certification is Plaid’s, not ours. When a user links accounts, Parity retrieves account balances, transaction history (typically 24 months: date, merchant, amount, category), and account metadata (institution, account type, account name). Parity never receives routing numbers or full account numbers.

Encryption

All account data, linked or entered manually, is encrypted at rest in Parity’s database using AES-256, and in transit using TLS 1.2 or higher.

De-identification and AI

Every profile is stripped of personally identifiable information before it is analyzed. AI providers never receive PII — only the minimum de-identified context. Enterprise AI APIs under contract — never public consumer tools. Contracts prohibit training on submitted data and nothing is retained. Requests are stateless and de-identified, with no commingling between institutions. The core tools work without AI — Savvy and insights are fully opt-in.

Vendor management

Vendors pass an annual security review and must report breaches immediately. Vendor security reviews are overseen by our CTO/CISO, whose background spans the Federal Reserve, hospital systems, and energy-sector environments.

User control and deletion

Linking accounts and AI features are both optional. Anyone can request full deletion of their data at any time.

Data retention

User data is retained for the duration of the account relationship. On account termination or user request, data is purged from our systems. Financial data is not retained beyond its operational use.

Sub-processors

Every infrastructure vendor we run on holds SOC 2 Type II — Google Cloud Platform (also ISO 27001), MongoDB Atlas (also ISO 27001), Plaid, Stripe (also PCI-DSS Level 1), and Cloudflare. The Zillennial Advisors does not itself hold a SOC 2 Type II certification.

What the institution can and cannot see about an individual

Institutions receive aggregate program reporting only. Numbers are aggregate; no individual is identified.

05 · Security controls

Control by control, with the status we can actually attest to.

Security control status
ControlEncryption in transitStatusTLS 1.2+
ControlEncryption at restStatusAES-256
ControlBank credentialsStatusNever seen or stored. Accounts link through Plaid, which is SOC 2 Type II certified.
ControlPII sent to AI providersStatusNone. Profiles are de-identified before analysis; enterprise APIs only; no training on submitted data, nothing retained.
ControlVendor managementStatusAnnual security review, immediate breach reporting required, overseen by our CTO/CISO.
ControlUser control and deletionStatusAggregation and AI are opt-in. Full deletion available on request at any time.
ControlAccess control and least privilegeStatusLeast-privilege model; mandatory two-factor authentication for all team members; 16-character minimum passphrases; access revoked immediately on departure.
ControlAccess reviewsStatusSemi-annual access privilege audits.
ControlLogging and monitoringStatusActivity logging and monitoring in place.
ControlIncident responseStatusDocumented incident response procedures.
ControlSecurity trainingStatusRegular employee security training.
ControlPatchingStatusAutomatic security updates across all systems.
ControlFormal data retention scheduleStatusData is retained for the duration of the account relationship and purged on termination or request; financial data is not retained beyond its operational use.
ControlSOC 2 status (ours)StatusEvery infrastructure vendor we run on holds SOC 2 Type II — Google Cloud Platform, MongoDB Atlas, Plaid, Stripe, and Cloudflare. The Zillennial Advisors does not itself hold a SOC 2 Type II certification.
ControlMost recent penetration testStatusConducted annually.
06 · Accessibility

Accessibility conformance.

Both platforms have completed WCAG 2.1 Level AA accessibility assessments. VPATs are published for Parity and Wealth Academy; both currently show partial conformance with identified gaps and active remediation — primarily color contrast and heading structure.

07 · Compliance program

How the advisory side is supervised.

The Adviser maintains written policies and procedures, a designated Chief Compliance Officer, and an annual review. Marketing materials are reviewed and approved before distribution and retained on a compliance archive. People who promote the Adviser are subject to written oversight, disclosure requirements, and training, and are never compensated per signup.

08 · Participant protections

What the people you serve are and aren't exposed to.

  1. 01

    Individual investment advice is delivered only inside the Parity platform, by the registered adviser. Not by email, not by phone, not in a classroom.

  2. 02

    Wealth Academy content is educational and generic. It does not tell an individual what to do with their money.

  3. 03

    Facilitators, educators, and campus representatives do not answer individual financial questions. Those route to the firm.

  4. 04

    No one is compensated per signup.

Request the diligence packet.

Security questionnaire responses, entity documentation, agreement templates, and available certifications. Tell us which questionnaire your organization uses and we'll answer it directly.