Security

Your leads are yours.
Guaranteed by the database.

Isolation isn’t a setting you trust us to honour - it’s enforced at the row level in Postgres, underneath the application.

Row-level isolation

Every workspace’s data is scoped by Postgres row-level security - a database-level guarantee that one tenant can never read another’s rows, not an app filter we hope nobody forgets.

Your own credentials

Your Meta pixel/token, GA4 keys, WhatsApp number, Razorpay and SMTP live in your workspace and are used only for your sends and conversions.

Hashed PII in conversions

Personal data sent to Meta CAPI is hashed (SHA-256) per their spec; GA4 receives no PII at all, per Google policy.

Least-privilege access

Granular per-module roles, read-only analysts, and a separate platform-admin boundary keep access scoped to what each person needs.

Auditable actions

Email, webhook and billing events are logged, so there’s a trail for what was sent and when.

Encrypted in transit

All traffic is served over TLS; API keys are stored as one-way hashes and shown only once.

Security questions for a larger deployment? Talk to us - we’re happy to walk through the architecture.

Close the loop on your next lead

Stop guessing which ads
actually made you money.

Spin up your workspace in minutes and watch the loop close on your very first lead. Free Starter plan, 14-day Growth trial, no card required.