Skip to content

Security

What we actually do to protect your data

A plain description of the controls implemented in Deltryx today — each one in the code and, where noted, covered by automated tests. We do not hold third-party certifications and do not claim any.

What we actually do to protect your data

Tenant isolation at the database

Row-level security on every customer table. The application connects with a role that cannot bypass it, and every query runs inside a transaction scoped to your organisation.

  • Secret columns are hidden from the application role by column grants
  • Isolation tests for every feature area

Encryption of secrets

Platform tokens, webhook secrets and API keys are encrypted at rest with AES-256-GCM and a random IV per operation. Server keys and share links are stored only as hashes.

Accounts and sessions

Passwords are hashed with scrypt. Two-step verification with TOTP and recovery codes, with an organisation-wide requirement if you want one.

  • Opaque session tokens stored as hashes, HttpOnly and SameSite cookies
  • Idle expiry after seven days, absolute expiry after fourteen
  • List and end your sessions; password changes end the others

Access control and audit

Six roles — owner, admin, analyst, media buyer, viewer and client — checked on the server for every page and action. An audit log records who did what, to what, and when, and can be exported.

Hardened public endpoints

Rate limits before password hashing, signed store webhooks compared in constant time, replay protection by delivery ID, and bot filtering on the pixel.

Browser protections

A content security policy with a per-request nonce and no inline scripts, HSTS, frame denial, no MIME sniffing and a strict referrer policy.

Personal data minimisation

Customer email and phone are stored as SHA-256 hashes; raw payload archives are scrubbed of identifiers and expire after 90 days. Privacy requests to export or erase a person's data are built in.

AI with guardrails

Deltryx AI has read-only tools scoped to your workspace, treats your content as data rather than instructions, and cannot execute changes without a person's approval.

Reporting a vulnerability

If you believe you have found a security issue, email [email protected] with the subject "Security" and the details. Please give us reasonable time to fix it before disclosing it publicly.

Questions, answered plainly

Are you SOC-audited or ISO-certified?

Not at this time. We prefer to describe what is implemented rather than display badges we have not earned.

Where is my data hosted?

On servers hosted by Hostinger, behind Cloudflare's network. See the subprocessor list in our privacy policy.

Do you support single sign-on?

Not yet. SAML and OIDC single sign-on are not built; two-step verification is available for every account.

See your own numbers, labelled honestly

Start a free trial and connect a store and an ad account, or book a walkthrough with our team.