Controls
Last reviewed July 2026Infrastructure security
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Cloudflare Web Application Firewall (WAF) and DDoS protection
- Encrypted backups with tested restore procedures
- Isolated production, staging, and development environments
- Vulnerability scanning and dependency scanning in CI/CD
Organizational security
- Information security policy
- Risk management program
- Internal security audits
- Personnel security and background checks
- Vendor risk assessments for all subprocessors
- Incident response procedures with customer notification
- Business continuity and disaster recovery planning
Product security
- Secure development life cycle with code review before merge
- HTTPS-only destination URL validation
- Creative upload validation and advertising-platform policy checks
- Multi-step approval workflows for campaign launches
- Budget limits and spending alerts
- Static and dynamic application security testing (SAST/DAST)
Access control
- Passwordless authentication via Google OAuth SSO, email magic links / OTP, and WorkOS SSO for eligible organisations
- MFA available via Google / IdP when organisation-enforced
- Role-based team access management
- Privileged access management and least privilege
- OAuth-scoped platform tokens, revocable at any time
Data and privacy
- Data Processing Agreement (DPA)
- Data classification and handling standards
- GDPR data subject rights support
- Breach notification per GDPR Article 33
- Customer data deleted within 30 days of termination (backups purged within 90 days)
- Sanctions compliance screening
- No PHI required for standard platform use