01Tenant isolation at the database
Row-level security on every customer table. The application connects with a role that cannot bypass it, and every query runs inside a transaction scoped to your organisation.
- Secret columns are hidden from the application role by column grants
- Isolation tests for every feature area
02Encryption of secrets
Platform tokens, webhook secrets and API keys are encrypted at rest with AES-256-GCM and a random IV per operation. Server keys and share links are stored only as hashes.
03Accounts and sessions
Passwords are hashed with scrypt. Two-step verification with TOTP and recovery codes, with an organisation-wide requirement if you want one.
- Opaque session tokens stored as hashes, HttpOnly and SameSite cookies
- Idle expiry after seven days, absolute expiry after fourteen
- List and end your sessions; password changes end the others
04Access control and audit
Six roles — owner, admin, analyst, media buyer, viewer and client — checked on the server for every page and action. An audit log records who did what, to what, and when, and can be exported.
05Hardened public endpoints
Rate limits before password hashing, signed store webhooks compared in constant time, replay protection by delivery ID, and bot filtering on the pixel.
06Browser protections
A content security policy with a per-request nonce and no inline scripts, HSTS, frame denial, no MIME sniffing and a strict referrer policy.
07Personal data minimisation
Customer email and phone are stored as SHA-256 hashes; raw payload archives are scrubbed of identifiers and expire after 90 days. Privacy requests to export or erase a person's data are built in.
08AI with guardrails
Deltryx AI has read-only tools scoped to your workspace, treats your content as data rather than instructions, and cannot execute changes without a person's approval.