For the people who have to sign off.
Regulatory standing, entity structure, data handling, and controls. Where we don't yet have a document to hand you, this page says so rather than implying we do.
Request the diligence packet
Who is registered, and for what.
The Zillennial Advisors LLC is an SEC-registered investment adviser, CRD #324808, SEC File No. 801-133744. It delivers investment advice through the Parity platform. Registration does not imply a certain level of skill or training.
Wealth Academy LLC operates the Wealth Academy education platform. It is not an investment adviser and does not provide investment advice.
Who you'd be contracting with.
- The Zillennial Advisors Inc.
- Parent company. Employs personnel, operates this website. Not a registered adviser.
- The Zillennial Advisors LLC
- The SEC-registered investment adviser. Operates Parity. Any individual advisory relationship is with this entity, executed by the individual through the platform.
- Wealth Academy LLC
- Operates the Wealth Academy education platform.
The signing entity varies by service: advisory services are provided by The Zillennial Advisors LLC; educational programs are delivered by Wealth Academy LLC. Which entity signs depends on the services in scope.
The Zillennial Advisors Inc.
Parent company · operates this website
The Zillennial Advisors LLC
SEC-registered investment adviser. CRD #324808 · SEC File No. 801-133744. Delivers advice through the Parity platform.
Advice
Wealth Academy LLC
Operates the Wealth Academy education platform. Does not provide investment advice.
Education
What we collect and what we do with it.
We do not sell data.
- What is collected, and only ever voluntarily
Account basics: name, email, date of birth. Financial profile: income, expenses, goals, risk tolerance. If Plaid is linked, which is optional: balances and transaction history. Plus platform usage metrics. Every field beyond name and email is optional.
- What Parity never does
Never sees or stores bank login credentials. Never shares personal information with other entities. Does not collect Social Security numbers or government IDs outside optional investing KYC. Never uses your data to train AI models.
- Account aggregation
Accounts link through Plaid; users log in directly with their bank. Credentials are never seen or stored by ZA. Plaid is SOC 2 Type II certified — that certification is Plaid’s, not ours. When a user links accounts, Parity retrieves account balances, transaction history (typically 24 months: date, merchant, amount, category), and account metadata (institution, account type, account name). Parity never receives routing numbers or full account numbers.
- Encryption
All account data, linked or entered manually, is encrypted at rest in Parity’s database using AES-256, and in transit using TLS 1.2 or higher.
- De-identification and AI
Every profile is stripped of personally identifiable information before it is analyzed. AI providers never receive PII — only the minimum de-identified context. Enterprise AI APIs under contract — never public consumer tools. Contracts prohibit training on submitted data and nothing is retained. Requests are stateless and de-identified, with no commingling between institutions. The core tools work without AI — Savvy and insights are fully opt-in.
- Vendor management
Vendors pass an annual security review and must report breaches immediately. Vendor security reviews are overseen by our CTO/CISO, whose background spans the Federal Reserve, hospital systems, and energy-sector environments.
- User control and deletion
Linking accounts and AI features are both optional. Anyone can request full deletion of their data at any time.
- Data retention
User data is retained for the duration of the account relationship. On account termination or user request, data is purged from our systems. Financial data is not retained beyond its operational use.
- Sub-processors
Every infrastructure vendor we run on holds SOC 2 Type II — Google Cloud Platform (also ISO 27001), MongoDB Atlas (also ISO 27001), Plaid, Stripe (also PCI-DSS Level 1), and Cloudflare. The Zillennial Advisors does not itself hold a SOC 2 Type II certification.
- What the institution can and cannot see about an individual
Institutions receive aggregate program reporting only. Numbers are aggregate; no individual is identified.
Control by control, with the status we can actually attest to.
| Control | Status |
|---|---|
| ControlEncryption in transit | StatusTLS 1.2+ |
| ControlEncryption at rest | StatusAES-256 |
| ControlBank credentials | StatusNever seen or stored. Accounts link through Plaid, which is SOC 2 Type II certified. |
| ControlPII sent to AI providers | StatusNone. Profiles are de-identified before analysis; enterprise APIs only; no training on submitted data, nothing retained. |
| ControlVendor management | StatusAnnual security review, immediate breach reporting required, overseen by our CTO/CISO. |
| ControlUser control and deletion | StatusAggregation and AI are opt-in. Full deletion available on request at any time. |
| ControlAccess control and least privilege | StatusLeast-privilege model; mandatory two-factor authentication for all team members; 16-character minimum passphrases; access revoked immediately on departure. |
| ControlAccess reviews | StatusSemi-annual access privilege audits. |
| ControlLogging and monitoring | StatusActivity logging and monitoring in place. |
| ControlIncident response | StatusDocumented incident response procedures. |
| ControlSecurity training | StatusRegular employee security training. |
| ControlPatching | StatusAutomatic security updates across all systems. |
| ControlFormal data retention schedule | StatusData is retained for the duration of the account relationship and purged on termination or request; financial data is not retained beyond its operational use. |
| ControlSOC 2 status (ours) | StatusEvery infrastructure vendor we run on holds SOC 2 Type II — Google Cloud Platform, MongoDB Atlas, Plaid, Stripe, and Cloudflare. The Zillennial Advisors does not itself hold a SOC 2 Type II certification. |
| ControlMost recent penetration test | StatusConducted annually. |
Accessibility conformance.
Both platforms have completed WCAG 2.1 Level AA accessibility assessments. VPATs are published for Parity and Wealth Academy; both currently show partial conformance with identified gaps and active remediation — primarily color contrast and heading structure.
Accessibility documents
How the advisory side is supervised.
The Adviser maintains written policies and procedures, a designated Chief Compliance Officer, and an annual review. Marketing materials are reviewed and approved before distribution and retained on a compliance archive. People who promote the Adviser are subject to written oversight, disclosure requirements, and training, and are never compensated per signup.
What the people you serve are and aren't exposed to.
- 01
Individual investment advice is delivered only inside the Parity platform, by the registered adviser. Not by email, not by phone, not in a classroom.
- 02
Wealth Academy content is educational and generic. It does not tell an individual what to do with their money.
- 03
Facilitators, educators, and campus representatives do not answer individual financial questions. Those route to the firm.
- 04
No one is compensated per signup.
Request the diligence packet.
Security questionnaire responses, entity documentation, agreement templates, and available certifications. Tell us which questionnaire your organization uses and we'll answer it directly.