Security
Your customers are yours. Guaranteed by the database.
Isolation is not a setting you trust us to honour. It is enforced at the row level in Postgres, underneath the application - and everything else on this page is built the same way: in the code, not in a policy.
Row-level isolation
Every workspace’s data is scoped by Postgres row-level security - a database-level guarantee that one tenant can never read another’s rows, not an app filter we hope nobody forgets.
Your own credentials
Your Meta pixel/token, GA4 keys, WhatsApp number, Razorpay and SMTP live in your workspace and are used only for your sends and conversions.
Hashed PII in conversions
Personal data sent to Meta CAPI is hashed (SHA-256) per their spec; GA4 receives no PII at all, per Google policy.
Least-privilege access
Granular per-module roles, read-only analysts, and a separate platform-admin boundary keep access scoped to what each person needs.
Auditable actions
Email, webhook and billing events are logged, so there’s a trail for what was sent and when.
Encrypted in transit
All traffic is served over TLS; API keys are stored as one-way hashes and shown only once.
Secrets encrypted at rest
Every integration credential - Meta tokens, WhatsApp, Razorpay, SMTP - is encrypted before it is stored, and a blank on a settings form keeps the stored secret rather than wiping it.
Backups every 15 minutes
A full database dump every fifteen minutes, deduplicated into an encrypted off-site store with every point kept for 30 days, plus daily copies in a second location. Restores are rehearsed, not assumed.
Releases with no downtime
Two API instances behind one gateway; a release recreates the standby first, then the primary, and a broken build fails while the old one is still serving. A Shopify webhook never meets a closed door.
Health data never leaves
For sensitive verticals, product and category names that would reveal a health condition are stripped from every conversion before it is posted to any ad platform.
Hosted in the EU
Production runs on dedicated infrastructure in Helsinki, Finland, on hardware we operate, not a shared multi-tenant host.
Scope enforced at the API
A read-only analyst, a department-scoped rep, an agency member entering a client workspace: each limit is checked on every request server-side, never only hidden in the interface.
Webhooks are idempotent
A Shopify webhook re-delivered three times creates one order and fires one automation. Three guards, and a database index that makes the duplicate impossible.
Google user data, limited use
Calendar, Gmail and Google Ads access do only the job you connected them for. We never sell Google user data, never use it for advertising, and never read a mailbox.
What we never do
Six lines the product does not cross.
Read or store a customer’s mailbox
Share one workspace’s data with another, even inside an agency
Send a conversion without hashing the identifiers first
Keep a secret in plain text, on disk or on screen
Deploy by taking the API offline
Train anything on your customers’ data
Security questions for a larger deployment? Talk to us - we’re happy to walk through the architecture.
Close the loop on your next lead
Transform your brand with signals.Your first order, credited, in ten minutes.
Measurement first, then everything else. Spin up your workspace in minutes and watch the first signal go back on your very first order. 30-day free trial, no card required.