Security, in plain words.

If you are doing due diligence on us, this page is for you. How we take access, who can see what, how the portal is protected, and what happens when you leave. Written for owners and partners, not lawyers.

Access

How we take ad account access

01

Platform partner delegation, never passwords

On Meta, you add CurrentAds as a partner through your Business Manager and grant access to the specific ad account, page, and pixel. On Google, we request manager (MCC) access to your Google Ads account and you approve it from your side. TikTok, LinkedIn, and the other platforms work the same way: a delegation you grant, visible in your settings, revocable by you at any time. We never ask for your password, and if anyone claiming to be us ever does, refuse and email us.

02

Least privilege by default

We request the lowest permission level that lets us do the job. Analyst or advertiser roles where they suffice, admin only where a platform genuinely requires it for setup, and we tell you which and why before you grant anything. We do not ask for access to assets we are not managing.

03

Everything stays in your name

Ad accounts, pixels, audiences, and pages are created under your ownership, not ours. Our access is a guest key to your building. You can see every person and partner with access in your own platform settings, and nothing about our setup prevents you from removing us in two clicks.

Visibility

Who can see what

01

Named senior buyers per account

Each client account is worked by named senior media buyers assigned to it. You know who they are from kickoff, and access inside CurrentAds follows that assignment rather than being open to everyone on staff.

02

No offshore data resale

Your account data is not handed to offshore resale operations or anonymous outsourcing chains. The people with access to your account are the people working your account.

03

We do not sell or share client data

Your performance data, customer lists, and audiences are yours. We do not sell them, share them with other clients, pool them into products, or use them to advantage a competitor. White-label partners see only the accounts they bring us, never anyone else's.

Portal

Portal security, without the jargon

The live client portal holds your reporting and plans, so here is exactly how it is protected, in words that do not require an engineering degree.

01

Individual logins

Every user gets their own account. No shared team passwords floating around a group chat.

02

Hashed passwords

Passwords are stored as one-way hashes. We could not read your password if we wanted to, and neither could someone who stole the database.

03

Rate limited sign-in

Repeated failed login attempts get slowed and blocked, which is what shuts down password guessing attacks.

04

Sessions that expire

Logins do not last forever. Stale sessions time out, so a laptop left open at a coffee shop is a bounded problem, not a permanent one.

05

HTTPS everywhere

Every page and every request is encrypted in transit. There is no unencrypted version of the portal.

06

Security headers

The portal ships standard browser protections: content security policy, frame blocking, and strict transport rules that tell browsers to refuse insecure connections.

Leaving

Offboarding, same day

Every engagement is month to month, so the exit needs to be as clean as the entrance. When you leave:

  • Our access is revoked the same day you end the engagement, and you can verify it yourself in each platform's partner settings
  • You keep your ad accounts, audiences, pixels, pages, and creative, because they were always in your name
  • You get a data export on request: campaign structures, performance history, and reporting
  • No offboarding fees, no data export fees, no ransom for your own accounts

This is the same policy behind our 30 day guarantee: you should stay because it works, never because leaving is expensive.

Honesty

What we do not claim

We do not hold a SOC 2 certification, and we will not decorate this page with badges that imply otherwise. Plenty of agencies paste compliance logos they have no right to; we would rather tell you plainly what we do and let you judge it.

If your due diligence needs more than this page covers, ask. Send security questions to contact@currentads.net and a real person will answer them specifically, including questions from your IT team or a white-label partner's client.

Diligence done? Start with the plan.