Controls
Last reviewed July 2026Infrastructure security
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Cloudflare Web Application Firewall (WAF) and DDoS protection
- Encrypted backups with tested restore procedures
- Isolated production, staging, and development environments
- Vulnerability scanning and dependency scanning in CI/CD
Organizational security
- Information security policy
- Risk management program
- Internal security audits
- Personnel security and background checks
- Vendor risk assessments for all subprocessors
- Incident response procedures with customer notification
- Business continuity and disaster recovery planning
Product security
- Secure development life cycle with code review before merge
- HTTPS-only destination URL validation
- Creative upload validation and advertising-platform policy checks
- Multi-step approval workflows for campaign launches
- Budget limits and spending alerts
- Static and dynamic application security testing (SAST/DAST)
Access control
- Passwordless authentication via Google OAuth SSO, email magic links / OTP, and WorkOS SSO for eligible organisations
- MFA available via Google / IdP when organisation-enforced
- Role-based team access management
- Privileged access management and least privilege
- OAuth-scoped platform tokens, revocable at any time
Data and privacy
- Data Processing Agreement (DPA)
- Data classification and handling standards
- GDPR data subject rights support
- Breach notification per GDPR Article 33
- Customer data deleted within 30 days of termination (backups purged within 90 days)
- Sanctions compliance screening
- No PHI required for standard platform use
Data collected
Customer contact details
Name, email, and workspace settings needed to run your account.
Ad account and campaign data
Campaigns, creatives, and performance data accessed through official platform APIs.
Credit card numbers
Payments are processed by Stripe — card details never touch our servers.
Personal health information
AdManage does not require or intentionally collect PHI for standard platform use.
Subprocessors
View all
PlanetScale • Database
Database hosting and management. SOC 2 Type II certified, encryption at rest and in transit. (USA)

Railway • Application hosting
Application hosting in isolated container environments. SOC 2 Type II certified. (USA)

Google Cloud Platform • Cloud provider
BigQuery data warehousing and Gemini AI services. SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018 certified. (USA / EU)

Cloudflare • CDN and storage
CDN, WAF, DDoS protection, and media storage (R2). SOC 2 Type II, ISO 27001 certified. (USA)

Upstash • Caching
Redis caching services. SOC 2 Type II certified, data encrypted at rest. (USA)
Stripe • Payments
Subscription billing and payment processing. Card details are handled by Stripe and do not touch AdManage servers. PCI DSS Level 1, SOC 2 Type II. (USA)
Resend • Email
Transactional email delivery (sign-in links, notifications). SOC 2 Type II. (USA)
Sentry • Monitoring
Application error monitoring and diagnostics. SOC 2 Type II. (USA)
PostHog • Product analytics
Product analytics to improve the AdManage application experience. SOC 2 Type II. (USA / EU)
Ad platforms you connect (Meta, TikTok, Google Ads, and the other channels) are integrations you authorize directly and are governed by their own terms — they are not subprocessors.