Security & compliance

Enterprise-Grade Security

Your data deserves the highest level of protection. We take security seriously from day one.

Certifications & standards

Compliance framework

SOC 2 ready

Controls documented

Security controls aligned with SOC 2 Type II requirements. Formal audit planned for end of 2026.

ISO 27001 aligned

Framework adopted

Information security management following international ISO 27001 standards.

GDPR-compliant by design

Privacy details linked

Read how we support data subject rights and protect personal data in our privacy policy.

European hosting

EU infrastructure

Runs on European infrastructure. Application, database, cache and site all run in the EU. Payments and email run in the US under EU-US DPF and SCCs. See our sub-processor list.

Certification roadmap

We're committed to building a strong security foundation. As we grow, we're working towards formal certifications:

  • Now: SOC 2 & ISO 27001 controls designed and documented
  • End of 2026: Penetration testing by external security firm
  • End of 2026: SOC 2 Type II audit initiation
  • 2027: ISO 27001 certification

Controls

Technical security controls

Data protection

  • AES-128-CBC with HMAC-SHA256 authenticated encryption for all OAuth tokens at rest
  • TLS 1.2 or higher encryption for all data in transit
  • Brief ad data caching - Ad data is fetched on demand and not retained long term. API responses are cached briefly (1 minute to 6 hours) to reduce load on the ad platforms.
  • Encrypted database connections with SSL certificates
  • API keys kept as SHA-256 hashes - we hold the hash, not the key itself

Access control

  • OAuth 2.0 with minimal required scopes per platform
  • Two-factor authentication (2FA) available for all accounts
  • Read-only by default - write access requires explicit tools
  • Per-account access control for team plans - assign specific ad accounts to members. Owners and admins always see every account in their workspace, by design: they are the ones who assign.
  • Revoke access anytime from dashboard or platform side

Infrastructure

  • EU-based hosting on Railway (backend) and Vercel (frontend)
  • Supabase PostgreSQL with automatic backups in EU region
  • Upstash Redis for caching with EU data residency
  • DDoS protection via Cloudflare and provider firewalls
  • Dependency audits with automated checks on each deployment

Monitoring & audit

  • Administrative actions on our platform are logged.
  • Real-time error tracking with Sentry for rapid response
  • Uptime monitoring with 5-minute intervals via UptimeRobot
  • Rate limiting to prevent abuse and ensure fair usage
  • Distributed tracing with OpenTelemetry for observability

For procurement

Security documents

The artifacts an evaluator asks for, and where to find each one. Public documents link straight through; the rest ship on request.

  • Data Processing Agreement (DPA)

    Controller-to-processor terms for client data.

    On request
  • Every third party that touches data, and where it runs.

    Public
  • Controls, hosting, encryption and access model: this page.

    Public
  • Dated path to SOC 2 Type II and ISO 27001.

    Public
  • Vendor security questionnaire

    Completed responses for procurement reviews.

    On request

Data & AI

AI & data privacy

AI training: what we control, and what you control

  • We do not operate AI models. Ad Superpowers moves data between the ad platforms and the AI tool you choose. Model training happens, if at all, inside that tool under your own agreement with its provider.
  • Claude (Anthropic) processes MCP tool results in-memory to answer your question. Whether those conversations feed model training is governed by your Anthropic plan and settings, which you control.
  • Your credentials stay with you. OAuth tokens are encrypted and stored in our database, never shared with AI providers.
  • We never sell your data. Your advertising data is yours. We don't monetize it, share it, or use it for any purpose other than providing the service.
Read full data privacy documentation

For agencies & enterprise

If you're an agency managing client ad accounts or an enterprise with strict security requirements, we understand your needs:

What we provide

  • Security documentation on request
  • Data Processing Agreement (DPA)
  • Vendor security questionnaire responses
  • Custom security reviews for Enterprise tier

Enterprise features

  • Custom usage and volume pricing
  • Advanced audit logging
  • Priority support via email
  • Custom integrations on request

Responsible disclosure

Found a security vulnerability? We appreciate responsible disclosure and will work with you to address any issues promptly.

Report a vulnerability

Take it to your security team

Governed access your clients can trust

Read-only by default, per-account scoping, encrypted tokens and EU hosting. Start a 14-day trial and see the controls for yourself.

14-day Pro or Team trial available

Cookies on this site

We use analytics cookies to see how the site is used. They load only if you accept, and you can change your choice at any time. Read our privacy policy.