Blog · 8 guides
Security & privacy
How AdAce Ads protects accounts and data: two-factor authentication, strict data isolation between workspaces and clients, encrypted credentials, access revocation on disconnect and a clear privacy policy.
Two-factor authentication with an authenticator app
Protect sign-in and sensitive actions with time-based one-time codes and 10 backup codes; required for owners and admins.
Data isolation between workspaces and clients
Row-level security in the database keeps every workspace and client separate — even a bug in a query cannot reveal another agency's data.
Encrypted credentials and secrets that never leave the server
Platform tokens are encrypted at rest, API keys and links are stored as hashes, and secrets never reach logs, AI models or browsers.
Disconnect a platform and revoke access at the provider
Disconnecting Google, Meta or Klaviyo revokes the service's access at the provider too, with durable retries — not just in the app.
Privacy and data handling
Data is used only to provide the service, never sold or used for advertising; Meta data deletion callbacks are supported.
Sign-in security: verified email, rate limits and sessions
Accounts are created with a verified email, sign-in attempts are rate-limited, and sessions are bound, revocable and closed on deactivation.
Review temporary advertising access by task, scope and exit date
Use an access card for temporary contractors: define the task, minimum client scope, review owner and evidence needed to close access.
Disconnect an AI client by reviewing grants, keys and provider access separately
Close an AI client's access with a boundary map for OAuth grants, API keys and provider connections, plus evidence of what was actually revoked.

Try it on your own accounts
Create a workspace, connect Google or Meta in a couple of clicks and see your accounts clearly. Changes follow your approvals or the policy you configure.