Security

Your ad data, protected.

Sentrum is built with a security-first architecture. You approve every change, encrypted storage, and enterprise-grade infrastructure — so you can focus on performance, not risk.

Data Protection

  • AES-256-GCM encryption for all stored tokens and credentials — the same standard used by banks and government agencies.
  • Approval-gated writes — Sentrum reads your data to diagnose. When write features are enabled, it applies only the change you approve: a pause or resume of a campaign, ad set, or ad, a schedule change to a campaign or ad set, or a new ad created as a paused draft. Every change is logged; status and schedule changes are reversible in one click.
  • Never budgets or bids — budget and bid changes are hard-blocked at the API layer. Sentrum cannot move money, no matter what you approve.
  • Data isolated per workspace — each workspace is a separate data silo. No cross-contamination between accounts.

Authentication & Access

  • Clerk-powered authentication — enterprise-grade identity management with MFA support, bot protection, and brute-force mitigation.
  • Session management with auto-expiry — inactive sessions are automatically terminated. Active sessions are continuously validated.
  • No password storage — authentication is fully delegated to Clerk. Sentrum never sees or stores your password.

Infrastructure

  • Hosted on Vercel — SOC 2 Type II compliant infrastructure with automatic DDoS protection, edge caching, and global CDN.
  • PostgreSQL on Neon — database encrypted at rest and in transit, with automated backups and point-in-time recovery.
  • All API calls over HTTPS/TLS 1.3 — every request between your browser, our servers, and third-party APIs is encrypted in transit.

Privacy & Compliance

  • GDPR data deletion endpoint — request full deletion of your data at any time. We process requests within 30 days.
  • Cookie consent with GA4 opt-out — analytics only run with your explicit consent. One click to opt out.
  • No third-party ad tracking — we don't run retargeting pixels, sell data to ad networks, or track you across the web.
  • For full details, read our Privacy Policy.

What We Don't Do

Trust is built on transparency. Here is what Sentrum will never do with your data:

  • Never copy your original ad creative files — we read creative metadata and cache small thumbnail previews so your reports keep rendering after Meta's short-lived CDN links expire; we don't download or retain the full-size creative files from your ad account. Assets you upload to or generate in Creative Studio are stored to make those features work.
  • Never share data between workspaces — your account data is yours alone, completely isolated from other users.
  • Never sell or share user data — your data is not a product. We make money from subscriptions, not data brokering.
  • Never change budgets or bids — hard-blocked at the API layer. The only writes Sentrum makes are the changes you explicitly approve — status, schedule, or paused draft ads — and every one is logged; status and schedule changes are reversible.

Questions about security?

We take data protection seriously. If you have questions about how Sentrum handles your data, reach out and we will respond within one business day.

Security | Sentrum