Merqad
How It WorksPricing
Sign InGet Started

Know what needs attention.

Connect your advertising accounts and let Merqad turn fragmented campaign data into clear, evidence-based decisions.

Get Started
Merqad

Advertising performance intelligence for teams who manage more than one account.

Product

  • Overview
  • Analytics
  • Waste Intelligence
  • Recommendations
  • Merqad Chat
  • Budget Planner

Solutions

  • Agencies
  • Marketing Teams
  • Growing Businesses
  • Enterprise

Resources

  • Security
  • Contact

Company

  • Contact
  • Privacy
  • Terms

© 2026 Merqad. All rights reserved.

info@merqad.com

Your data stays yours. Period.

Merqad is built security-first. Your ad accounts, campaign data, and recommendations are protected by multi-factor authentication, end-to-end encryption, and strict access controls — so unauthorized parties cannot reach your system or your data.

Last updated: June 2025

No one accesses your system or data without your authorization

Multi-factor authenticationOAuth-only ad connectionsEncrypted credentials at restTLS in transitWorkspace-scoped data accessMulti-factor authenticationOAuth-only ad connectionsEncrypted credentials at restTLS in transitWorkspace-scoped data access
No ad-platform password storageRole-based team permissionsSecure session handlingNo ad-platform password storageRole-based team permissionsSecure session handling

On this page

  • Our security commitment
  • Multi-Factor Authentication (MFA)
  • Who can access your data
  • Encryption — in transit and at rest
  • Ad platform connections (OAuth only)
  • Infrastructure & monitoring
  • Compliance & privacy
  • Report a security concern

Our security commitment

We treat your advertising data like financial data — because it is. Merqad is designed so that only you (and people you explicitly authorize) can access your account, your connected ad platforms, and your optimization history.

We never sell your data. We never use it to train models across customers. We never store your ad platform passwords. Security is not a feature we bolt on — it is how the product is built.

Multi-Factor Authentication (MFA)

Every Merqad account is protected with Multi-Factor Authentication (MFA). Signing in requires more than a password alone — you must verify your identity through a second factor before gaining access.

  • MFA is required for all users — there is no option to disable it
  • Supported methods include authenticator apps (TOTP), SMS, and hardware security keys where available
  • New devices and unfamiliar locations trigger additional verification steps
  • Session tokens expire automatically; inactive sessions are revoked

Even if someone obtained your Google login credentials, they still could not access your Merqad workspace without passing MFA on your authorized device.

Who can access your data

You, and only you. Your dashboard, recommendations, and synced campaign data are scoped exclusively to your account. Other Merqad customers cannot see your data — ever.

  • Strict tenant isolation: every query is scoped to your user ID
  • Merqad employees cannot browse customer ad data without a documented support request and your explicit permission
  • Internal tools require MFA, VPN, and role-based access with least-privilege permissions
  • All administrative access is logged and reviewed

Encryption — in transit and at rest

  • In transit: All traffic between your browser and our servers uses TLS 1.2 or higher. API calls to ad platforms are encrypted end-to-end.
  • At rest: OAuth tokens and sensitive credentials are encrypted with AES-256 via AWS KMS before they touch our database.
  • Database backups are encrypted and stored in geographically redundant locations.
  • Encryption keys are rotated and never stored alongside the data they protect.

Ad platform connections (OAuth only)

We never ask for — and never store — your Google Ads, Meta, TikTok, Microsoft, or Reddit passwords. Connections use OAuth 2.0, the same industry-standard protocol used by the platforms themselves.

  • You grant scoped permissions; we request only what we need to read metrics and apply your approved changes
  • Tokens are encrypted immediately upon receipt and stored in isolated, per-platform records
  • Disconnecting a platform revokes the token via the platform API and permanently deletes synced data from our systems

Infrastructure & monitoring

  • Hosted on AWS with network segmentation, firewalls, and DDoS protection
  • Automated vulnerability scanning and dependency updates on every release
  • 24/7 monitoring for suspicious login attempts, API anomalies, and unauthorized access patterns
  • Authentication events, API mutations, and admin actions written to immutable audit logs
  • Incident response plan with defined escalation and customer notification procedures

Compliance & privacy

Our security practices align with GDPR requirements for data protection and user rights. You can export or delete all personal and campaign data at any time. For full details on data collection and your rights, see our Privacy Policy.

Report a security concern

Found a vulnerability or have a security question? Email info@merqad.comwith the subject line "Security". We investigate all reports promptly and will not take legal action against good-faith security researchers who follow responsible disclosure.

Questions about security?

Ask about MFA, data access, encryption, or how we protect your ad accounts. We respond within one business day.

Contact usinfo@merqad.com