Trust
How we keep your data safe.
Equaliser handles paid-media performance data: campaign spend, revenue, customer acquisition cost. The kind of numbers that decide whether a brand grows or contracts. So we treat them with the same care your CFO does.
Security →
Runs on SOC 2 Type II attested infrastructure (Vercel, Supabase, Google Cloud); our own SOC 2 Type I attestation is in progress, Type II follows. AES-256 at rest, TLS 1.2+ enforced in transit, row-level isolation per organisation.
Sub-processors →
The full register: every third party that touches your data, the data they see, the region they store it in, dated on every change.
Privacy →
Built to UK GDPR principles, with the roadmap published on our Security page. We never sell your data or train models on it. Aggregated, de-identified usage patterns may be used to improve service reliability; they are never shared or sold.
DPA →
Standard data processing agreement, ready to counter-sign. Includes EU SCCs + UK IDTA.
The questions procurement asks first.
Where is data stored?
Primary data stores are in the EU/UK: Supabase (eu-west-2, London) and Google Cloud BigQuery (europe-west2, London), with application functions in the EU (Frankfurt) and US failover only under provider outage. Anthropic API calls use the EU endpoint where available, US otherwise, under a zero-retention agreement. Vercel serves static assets from a global edge network; application data does not persist outside the EU/UK except under failover.
Do you train models on customer data?
No. Anthropic API calls are sent with the no-training flag and zero-retention contract. We never fine-tune on customer data. We never embed customer content into a shared model.
How is one customer isolated from another?
Postgres Row-Level Security on every table that holds customer data. Policy keyed on org_id; service-role access is reserved for cron jobs that explicitly scope by org. BigQuery datasets are read-only via authorised views with org filters baked in.
What happens to data on account closure?
Deletion from live systems completes within 30 days of your election or termination, with a confirmation receipt. Encrypted backups roll off within a further 90 days (120 days in total). We retain only the minimum required for legal and tax purposes (invoice records).
Do you have a security questionnaire boilerplate?
Yes: email contact@equaliser.co.uk with your standard questionnaire (Whistic / OneTrust / SIG-Lite). We aim to turn these around within 5 UK working days.
Can we audit you?
Annual SOC 2 attestation reports from our infrastructure providers (Vercel, Supabase, Google Cloud) are available under NDA. Our own SOC 2 Type I attestation is in progress; Type II follows.
How do you handle credentials for ad accounts?
OAuth tokens are encrypted at rest in Supabase Vault (libsodium / AES-256). Refresh tokens never leave the server. Equaliser connects with read-only scopes and does not execute changes on your ad accounts. If per-action execution ships in the future, every action will require explicit human approval, under scopes you grant at that point and can revoke.
Contact.
One monitored mailbox for security, privacy and procurement: contact@equaliser.co.uk. A dedicated security address and a named data protection contact are being established. For product support, use the same address: during the founding-customer period replies come directly from the team, typically the same working day.
This page describes Equaliser's posture as of 3 September 2026 (hand-dated on each change). Material changes are recorded, dated, on the relevant page; the sub-processor register carries its own change date.