Back to home
Security

Your data stays yours. Period.

Merqad is built security-first. Your ad accounts, campaign data, and recommendations are protected by multi-factor authentication, end-to-end encryption, and strict access controls — so unauthorized parties cannot reach your system or your data.

Last updated: June 2025

No one accesses your system or data without your authorization

Multi-Factor Authentication (MFA)AES-256 encryption at restOAuth-only ad connectionsTLS 1.2+ in transitStrict tenant isolationMulti-Factor Authentication (MFA)AES-256 encryption at restOAuth-only ad connectionsTLS 1.2+ in transitStrict tenant isolation
Immutable audit logsZero password storage24/7 threat monitoringNo cross-customer data accessEncrypted database backupsImmutable audit logsZero password storage24/7 threat monitoringNo cross-customer data accessEncrypted database backups

Our security commitment

We treat your advertising data like financial data — because it is. Merqad is designed so that only you (and people you explicitly authorize) can access your account, your connected ad platforms, and your optimization history.

We never sell your data. We never use it to train models across customers. We never store your ad platform passwords. Security is not a feature we bolt on — it is how the product is built.

Multi-Factor Authentication (MFA)

Every Merqad account is protected with Multi-Factor Authentication (MFA). Signing in requires more than a password alone — you must verify your identity through a second factor before gaining access.

  • MFA is required for all users — there is no option to disable it
  • Supported methods include authenticator apps (TOTP), SMS, and hardware security keys where available
  • New devices and unfamiliar locations trigger additional verification steps
  • Session tokens expire automatically; inactive sessions are revoked

Even if someone obtained your Google login credentials, they still could not access your Merqad workspace without passing MFA on your authorized device.

Who can access your data

You, and only you. Your dashboard, recommendations, and synced campaign data are scoped exclusively to your account. Other Merqad customers cannot see your data — ever.

  • Strict tenant isolation: every query is scoped to your user ID
  • Merqad employees cannot browse customer ad data without a documented support request and your explicit permission
  • Internal tools require MFA, VPN, and role-based access with least-privilege permissions
  • All administrative access is logged and reviewed

Encryption — in transit and at rest

  • In transit: All traffic between your browser and our servers uses TLS 1.2 or higher. API calls to ad platforms are encrypted end-to-end.
  • At rest: OAuth tokens and sensitive credentials are encrypted with AES-256 via AWS KMS before they touch our database.
  • Database backups are encrypted and stored in geographically redundant locations.
  • Encryption keys are rotated and never stored alongside the data they protect.

Ad platform connections (OAuth only)

We never ask for — and never store — your Google Ads, Meta, TikTok, Microsoft, or Reddit passwords. Connections use OAuth 2.0, the same industry-standard protocol used by the platforms themselves.

  • You grant scoped permissions; we request only what we need to read metrics and apply your approved changes
  • Tokens are encrypted immediately upon receipt and stored in isolated, per-platform records
  • Disconnecting a platform revokes the token via the platform API and permanently deletes synced data from our systems

Infrastructure & monitoring

  • Hosted on AWS with network segmentation, firewalls, and DDoS protection
  • Automated vulnerability scanning and dependency updates on every release
  • 24/7 monitoring for suspicious login attempts, API anomalies, and unauthorized access patterns
  • Authentication events, API mutations, and admin actions written to immutable audit logs
  • Incident response plan with defined escalation and customer notification procedures

Compliance & privacy

Our security practices align with GDPR requirements for data protection and user rights. You can export or delete all personal and campaign data at any time. For full details on data collection and your rights, see our Privacy Policy.

Report a security concern

Found a vulnerability or have a security question? Email support@yourdomain.comwith the subject line "Security". We investigate all reports promptly and will not take legal action against good-faith security researchers who follow responsible disclosure.

Questions about security?

Ask about MFA, data access, encryption, or how we protect your ad accounts. We respond within one business day.