Security

Last updated: August 14, 2026

We apply a security-by-default principle at every layer of the platform. Below is a description of the technical measures in place. We do not claim certifications (ISO 27001, SOC 2, etc.) that have not yet been obtained.

Infrastructure

  • Data hosted on Supabase (EU-West region); storage encrypted at rest (AES-256)
  • All connections use TLS 1.2+; HSTS preload is active on the production domain
  • VPS: SSH-key-only access, password-based root login disabled
  • Nginx with restricted response headers; server version hidden

Authentication and authorisation

  • Authentication via Supabase Auth (bcrypt password hashes, JWT sessions)
  • TOTP MFA available and mandatory for agency_owner and platform_admin roles
  • Row-Level Security (RLS) at the database level — every query is isolated by agency_id
  • RBAC matrix: 5 roles, enforced in Server Actions and RLS
  • Rate limiting on all auth, AI, and mutation endpoints
  • HMAC-signed OAuth state + PKCE for Google Ads / Meta Ads integrations

Data protection

  • Ad account OAuth tokens encrypted with AES-256-GCM at the application layer
  • Logs pass through a redaction layer: API keys, JWTs, and OAuth tokens are stripped before writing
  • Stripe webhooks: HMAC signature verification, idempotency by event ID
  • File uploads: MIME type + magic byte validation + size limits
  • Content Security Policy: enforced mode (not report-only)

AI security

  • External content is sanitised before being passed to the LLM
  • Agents with reads_external_content=true cannot access action tools
  • Destructive mutations (budgets, publishing, deletion) require a policy gate or human approval
  • Provider: Anthropic Claude (SCC; no training on API data per contract terms)

SDLC and monitoring

  • CI: TypeScript, ESLint, Vitest (1056 tests), gitleaks secret scan, pnpm audit
  • Auto-deploy only after all CI checks pass
  • Sentry: error monitoring with source maps (not published to production)
  • Audit log of privileged actions in security_audit_log (90-day retention)
  • Retention cron: automated data deletion on schedule (daily at 03:00 UTC)

Vulnerability disclosure

If you discover a vulnerability, please report it to [email protected]. We will respond within 72 hours and coordinate a fix before public disclosure (responsible disclosure).

Privacy Policy · Sub-processors · Terms of Service

Security — Targics