Security and trust
What we do to protect your account and the consent data you collect, described as it works today.
Access control
Single sign-on (SAML)
Enterprise teams can require sign-in through their own identity provider using SAML single sign-on.
SCIM directory sync
On Enterprise, users can be provisioned and removed from your identity provider through SCIM 2.0.
Role-based permissions
Team members get owner, admin, publisher, editor or viewer permissions, and publishing a banner requires publish rights on that banner.
Credential storage
Passwords are stored as bcrypt hashes and API keys as hashes, never in plain text.
Data protection
Encrypted secrets
Secrets you give us, such as webhook endpoint URLs and the Meta Conversions API token for server-side GTM, are encrypted in the database with AES-256-GCM.
EU hosting
The application and database, including consent logs, run on Oracle Cloud Infrastructure in an EU region.
Accountability
Audit log
Team activity and banner changes are recorded in an append-only audit log, protected against deletion at the database level. Entries are kept for 2 years.
Signed consent receipts
Consent receipts are digitally signed (JWS, EdDSA), so anyone holding one can check that it has not been altered.
Legal documents
Reporting a vulnerability
If you think you have found a security issue, email [email protected] with "Security" in the subject line and enough detail for us to reproduce it. Please do not access other customers’ data, and give us reasonable time to fix the issue before you disclose it publicly.