Security
Last updated: August 14, 2026
We apply a security-by-default principle at every layer of the platform. Below is a description of the technical measures in place. We do not claim certifications (ISO 27001, SOC 2, etc.) that have not yet been obtained.
Infrastructure
- Data hosted on Supabase (EU-West region); storage encrypted at rest (AES-256)
- All connections use TLS 1.2+; HSTS preload is active on the production domain
- VPS: SSH-key-only access, password-based root login disabled
- Nginx with restricted response headers; server version hidden
Authentication and authorisation
- Authentication via Supabase Auth (bcrypt password hashes, JWT sessions)
- TOTP MFA available and mandatory for agency_owner and platform_admin roles
- Row-Level Security (RLS) at the database level — every query is isolated by agency_id
- RBAC matrix: 5 roles, enforced in Server Actions and RLS
- Rate limiting on all auth, AI, and mutation endpoints
- HMAC-signed OAuth state + PKCE for Google Ads / Meta Ads integrations
Data protection
- Ad account OAuth tokens encrypted with AES-256-GCM at the application layer
- Logs pass through a redaction layer: API keys, JWTs, and OAuth tokens are stripped before writing
- Stripe webhooks: HMAC signature verification, idempotency by event ID
- File uploads: MIME type + magic byte validation + size limits
- Content Security Policy: enforced mode (not report-only)
AI security
- External content is sanitised before being passed to the LLM
- Agents with reads_external_content=true cannot access action tools
- Destructive mutations (budgets, publishing, deletion) require a policy gate or human approval
- Provider: Anthropic Claude (SCC; no training on API data per contract terms)
SDLC and monitoring
- CI: TypeScript, ESLint, Vitest (1056 tests), gitleaks secret scan, pnpm audit
- Auto-deploy only after all CI checks pass
- Sentry: error monitoring with source maps (not published to production)
- Audit log of privileged actions in security_audit_log (90-day retention)
- Retention cron: automated data deletion on schedule (daily at 03:00 UTC)
Vulnerability disclosure
If you discover a vulnerability, please report it to [email protected]. We will respond within 72 hours and coordinate a fix before public disclosure (responsible disclosure).