Security illustration: data protection shield

Security

How we protect your data

Operato AI is still an early-stage company. We don't yet hold a formal certification like SOC 2 or ISO 27001 — those audits take time, and we're working toward them. In the meantime, here is exactly what we do today to protect your data, with nothing overstated.

Encryption at rest

Credentials for connected ad accounts and other sensitive fields are encrypted before they're stored, using a dedicated encryption key kept separate from the database itself.

Encryption in transit

Every connection to the platform, dashboard, and API runs over HTTPS with an automatically issued and renewed TLS certificate.

EU data residency

New accounts default to EU-based hosting. Every transfer of data to a third-party service is declared and logged in a technical register, along with the purpose of the transfer and the recipient's country.

Password handling

We never store a password in plain text. Every password is hashed with scrypt, a deliberately memory-hard function, which makes a stolen database expensive to attack rather than merely inconvenient.

Audit logging & rate limiting

Security-relevant actions (sign-in, account creation, support access) are logged. Public-facing endpoints are protected against abuse with request rate limiting.

Tenant isolation

Each customer's data is isolated at the data-access layer itself, not just in the interface, so a display bug can't expose another customer's data.

Questions about security?

Reach us at security@operato-ai.com. For how we handle personal data, see our Privacy Policy.

Chat on WhatsApp