Skip to main content

Security and trust

What we do to protect your account and the consent data you collect, described as it works today.

Access control

Single sign-on (SAML)

Enterprise teams can require sign-in through their own identity provider using SAML single sign-on.

SCIM directory sync

On Enterprise, users can be provisioned and removed from your identity provider through SCIM 2.0.

Role-based permissions

Team members get owner, admin, publisher, editor or viewer permissions, and publishing a banner requires publish rights on that banner.

Credential storage

Passwords are stored as bcrypt hashes and API keys as hashes, never in plain text.

Data protection

Encrypted secrets

Secrets you give us, such as webhook endpoint URLs and the Meta Conversions API token for server-side GTM, are encrypted in the database with AES-256-GCM.

EU hosting

The application and database, including consent logs, run on Oracle Cloud Infrastructure in an EU region.

Accountability

Audit log

Team activity and banner changes are recorded in an append-only audit log, protected against deletion at the database level. Entries are kept for 2 years.

Signed consent receipts

Consent receipts are digitally signed (JWS, EdDSA), so anyone holding one can check that it has not been altered.

Reporting a vulnerability

If you think you have found a security issue, email [email protected] with "Security" in the subject line and enough detail for us to reproduce it. Please do not access other customers’ data, and give us reasonable time to fix the issue before you disclose it publicly.

[email protected] · security.txt