Security
How we secure your paid-media data
Your ad platform data is sensitive. We treat it that way: encryption everywhere, organisation-level isolation, a redaction layer in front of AI processing, and a published roadmap for what is not finished yet.
Last updated: 3 September 2026
At a glance
- AES-256 encryption at rest; TLS 1.2+ enforced in transit (TLS 1.3 negotiated in practice)
- Row-level isolation per organisation, enforced in the database
- Primary data stores in the EU/UK; US failover only under provider outage
- Infrastructure SOC 2 Type II attested; our own Type I attestation in progress
- Zero-retention AI processing; no model training on customer data
SOC 2: Attested Infrastructure
Runs on SOC 2 Type II attested infrastructure (Vercel, Supabase, Google Cloud). Our own SOC 2 Type I attestation is in progress; Type II follows. Vendor attestation reports are available under NDA.
Encryption Everywhere
AES-256 encryption at rest across all data stores. TLS 1.2+ enforced in transit (connections negotiate TLS 1.3 in practice).
Organisation-Level Isolation
Tenant isolation is enforced at the database level (row-level security per organisation), not just in the application. Service-role access is reserved for scheduled jobs that scope explicitly by organisation.
PII and the AI Pipeline
AI agents analyse aggregated performance metrics: spend, clicks, conversions, ROAS. We do not ingest customer PII fields. Free-text fields such as search terms can incidentally contain personal data; a redaction layer strips common identifiers (emails, phone numbers, postcodes, National Insurance numbers, IP addresses) before any prompt leaves our systems.
Authentication & Access Control
Role-based access control (admin, strategist, client viewer), session management with automatic timeout, and two-factor authentication (TOTP) with in-product enrolment. Per-member two-factor state is visible to your admins in Settings. SSO via SAML/OIDC is on the roadmap below; we list it there, not here, until it ships.
Built to UK GDPR Principles
A signable Data Processing Addendum, a public sub-processor register, machine-readable data export from your account settings, and deletion requests recorded with an audit trail and completed within 30 days. Remaining work is tracked openly on the roadmap below.
Built on trusted infrastructure
Each infrastructure vendor holds its own independent attestation, shown per vendor below
Vercel
SOC 2 Type II, ISO 27001Application hosting & edge network
Google Cloud
SOC 2 Type II, ISO 27001/27017/27018BigQuery data warehouse
Supabase
SOC 2 Type IIDatabase, auth & real-time
Anthropic
SOC 2 Type II, ISO 27001AI processing (Claude API)
How we handle your data
What we store
- Aggregated campaign metrics (spend, clicks, conversions)
- Campaign and ad group names
- Search terms (for keyword analysis)
- GA4 session and revenue data
- Product feed attributes (for ecommerce)
- Shopify order and product aggregates (for ecommerce clients)
What we never store
- Customer personal information (names, emails, addresses)
- Payment or financial data
- Your ad platform passwords. We never see or store them; access is via OAuth tokens you grant, encrypted at rest in Supabase Vault, revocable at any time
- Raw click-stream or user-level event data
- Tracking cookies or pixels, on your customers or on you (our analytics run cookieless)
AI processing
- Only aggregated metrics sent to AI (Claude API)
- Anthropic does not train on API inputs
- Data Processing Agreement in place
- Incidental personal data in free text is redacted before any prompt leaves our systems
- All AI outputs are cached in your isolated database
Compliance roadmap
Have security questions? Need a DPA or compliance documentation? Security, privacy and procurement questions all reach one monitored mailbox; a dedicated security address is being established.
Contact us about securityFound a vulnerability? We welcome responsible disclosure: email contact@equaliser.co.uk and see /.well-known/security.txt.