Security
Access to client accounts is a serious responsibility
ABP.Marketing holds credentials that can change live advertising spend. The controls below describe how that access is contained, recorded and revocable — and where our compliance position actually stands.
Tenant isolation
Row level security, tested
Encrypted secrets
Server-side only, at rest
Least privilege
Narrowest workable scopes
Full audit trail
Actor, time and evidence
Decorative scene description: connected terrain zones for paid media, SEO and GEO, conversion rate optimisation and revenue outcomes send data streams into a central ABP.Marketing intelligence core.
Value
What these controls buy you
Security here is a delivery requirement, because the platform can act on live accounts.
Client data stays in its own lane
Every tenant table enforces row level security, and cross-tenant and cross-workspace denial are tested rather than assumed.
Isolation covered by automated tests
Credentials never leave the server
OAuth tokens and service keys are encrypted at rest and are never sent to the browser, logs, source control or error reports.
Envelope encryption with a managed key
Every consequential action is attributable
Proposals, approvals, executions, verifications, rollbacks and support access are recorded with actor, time and the evidence in view at the time.
Audit records are immutable and exportable
Controls
How the platform is protected
Tenancy
Row-level isolation
Every tenant table enforces row level security. Cross-tenant and cross-workspace denial are tested, not assumed.
Credentials
Encrypted, server-side only
OAuth tokens and service keys are encrypted at rest and never sent to the browser, logs, source control or error reports.
Scopes
Least privilege
Each connector requests the narrowest scopes that support its features, and the exact scopes are shown before you authorise.
Identity
MFA and roles
Multi-factor authentication for staff accounts, with granular roles for owners, strategists, analysts and client users.
Audit
Immutable trails
Proposals, approvals, executions, verifications, rollbacks and support access are recorded with actor, time and evidence.
Support access
Consent-based assumption
Operator support views require explicit authorisation, display a persistent banner, expire automatically and are fully audited.
Demo
What an audit record contains
If a change is ever questioned, this is the record your team produces.
Audit log — entry detail
Illustrative interface- Event
- Execution · pause ad group
- Actor
- Named approver · client role
- Authorisation
- Approval matrix · client tier
- Evidence at decision
- Finding v3 snapshot attached
- Bounds applied
- 1 object · expires 24h · reversible
- Provider response
- Accepted · request ID stored
- Verification
- Confirmed 5 minutes later
AI safety
What the model can and cannot do
- The model has no unrestricted database access and no generic provider call tool.
- The model explains deterministic calculations; it never produces source-of-truth figures.
- Model prompts and responses exclude credentials and are redacted before storage.
- Operators choose which models are permitted per task, behind a server-side abstraction.
Compliance status, stated plainly
We build to recognised control frameworks and maintain the readiness evidence for them. We do not claim SOC 2, ISO 27001 or any other certification we have not obtained, and we will tell you exactly where we are if you ask. Data processing terms are available in our data processing addendum.
Objection handling
Objections, answered directly
Send us your security questionnaire
We will answer it directly, including the questions where the honest answer is not yet.