Skip to content
Ads & Pixels

Ads and Pixels / Security

Security at Ads and Pixels

One stolen login could spend every client's ad budget. Here's what stops that from being possible.

01 / CONNECT02 / LAUNCH03 / KNOW
One place. Every screen.Explore below
01 /

Why this page exists

An agency using Ads and Pixels connects real ad accounts with real spending power — Meta, Google, Microsoft and every other network you link. A single compromised login isn't a minor incident in that context; it's every connected client's budget at risk at once. We built the platform's security around that specific threat, not around a generic checklist, and this page says plainly what's built, what's in progress, and what we don't claim yet.

02 /

Encrypted token storage

When you connect a platform — Meta, Google, TikTok, Microsoft or any other — the access token that lets Ads and Pixels act on your behalf is encrypted at rest. Those tokens are never returned to the browser in plain text once stored, and they're scoped to what each connection actually needs, following each network's own permission model rather than requesting broader access than a feature requires. Disconnecting a platform revokes the token on our side and, where the network's API supports it, on theirs.

Connected account · token protection
A scoped platform access token moves into encrypted storage represented by a padlock.
03 /

Two-factor authentication and passkeys

Every account can — and on agency and reseller tiers, must — enable two-factor authentication. We support passkeys as well as traditional authenticator-app codes, and Google and Microsoft single sign-on for teams that already manage identity centrally. Reseller-tier accounts can add SAML for their own team's login, so a white-labeled deployment can sit inside a larger organization's existing identity system rather than becoming a separate password to manage.

04 /

Roles, not one shared login

Every user on an account has a role — agency admin, campaign manager, approver, client viewer, and more — and every role limits what that person can see and do. Nobody needs a shared admin password to get their job done, and the roles that can spend money or approve an AI-proposed change are deliberately separate from the roles that can just view a report. This is the fix for a problem we've seen firsthand: a shared admin credential across a whole team or client roster is a liability the moment any one person's device or password is compromised, and it's avoidable by design rather than by policy alone.

05 /

An append-only audit log

Every meaningful action — a budget change, a campaign pause or launch, an AI-proposed change and who approved it, a permission grant, a platform connection or disconnection — is written to an audit log that can be added to but never edited or deleted, by anyone, including us. If something changes on an account, there's a record of who did it, when, and what it was before and after. This is the same log the MCP and API layers write to when an AI assistant proposes a change, so "an AI did something to my account" is never a question without an answer.

Account activity · illustrative log
An illustrative append-only account log with timestamped campaign, approval, and permission entries.
06 /

No passive tracking

We do not build passive Bluetooth or Wi-Fi tagging of people who haven't opted in, and we don't use cameras or face analysis on Local Screens or anywhere else. Every person tracked in an Audience Vault got there through an explicit, opt-in action — a form, a pixel event with consent, a rewards check-in, a Wi-Fi login with a stated opt-in — never by being detected passively in a location. This isn't just a policy choice: modern phones randomize the identifiers passive tracking depends on, several states now treat precise location as sensitive data requiring opt-in, and we'd rather not build something we'd have to defend later.

07 /

Where we are on formal certification

We're building toward SOC 2 — the access controls, audit logging and account-security groundwork on this page are, in part, exactly that preparatory work — but we do not currently hold a SOC 2 report, and we won't claim one until an independent auditor has actually issued it. If a formal SOC 2 report matters for your organization's vendor review today, ask us directly for current status before assuming it exists.

A little more clarity

Frequently asked questions

Real answers before you make a decision.

Do you have a SOC 2 report?

Not yet. We're building the controls SOC 2 requires — encrypted token storage, roles, an audit log, 2FA — as part of the platform itself, but we don't claim certification until an independent auditor has issued the report.

Can two-factor authentication be required for my whole team?

Yes, on agency and reseller tiers, an admin can require 2FA for every user on the account.

What happens to my platform tokens if I disconnect Meta or Google?

The stored token is revoked on our side immediately, and where the network's own API supports revocation, it's revoked there too.

Can an AI assistant using the MCP server spend my budget without approval?

Only within the same bounded autopilot limits a human already turned on for that client and action — pausing a clear loser, a budget move within ±20% — and nothing beyond that. Anything bigger (a new campaign, a new audience, published creative, a bid-strategy change, or any write on a client where autopilot is off) goes into an approval queue for a human with the Approver role. Either way, "approve" is never an available AI tool call, by design, not just by default setting — an assistant can propose or act inside pre-set bounds, but it can't click approve on its own behalf.

Do you track people who haven't opted in, on screens or anywhere else?

No. We don't build passive Bluetooth or Wi-Fi tagging, and we don't use cameras or face analysis. Everyone in an Audience Vault opted in through an explicit action.

Who can see the audit log?

Anyone with an appropriate role on the account (typically agency admins) can view the full log for that account. It's append-only, so it can be read and exported, but never edited or deleted.

Your next move

Connect real ad accounts with confidence

Encrypted tokens, roles instead of a shared login, and a record of every change — see it before you connect your first platform.