Security, in plain words.
If you are doing due diligence on us, this page is for you. How we take access, who can see what, how the portal is protected, and what happens when you leave. Written for owners and partners, not lawyers.
Access
How we take ad account access
01
Platform partner delegation, never passwords
On Meta, you add CurrentAds as a partner through your Business Manager and grant access to the specific ad account, page, and pixel. On Google, we request manager (MCC) access to your Google Ads account and you approve it from your side. TikTok, LinkedIn, and the other platforms work the same way: a delegation you grant, visible in your settings, revocable by you at any time. We never ask for your password, and if anyone claiming to be us ever does, refuse and email us.
02
Least privilege by default
We request the lowest permission level that lets us do the job. Analyst or advertiser roles where they suffice, admin only where a platform genuinely requires it for setup, and we tell you which and why before you grant anything. We do not ask for access to assets we are not managing.
03
Everything stays in your name
Ad accounts, pixels, audiences, and pages are created under your ownership, not ours. Our access is a guest key to your building. You can see every person and partner with access in your own platform settings, and nothing about our setup prevents you from removing us in two clicks.
Visibility
Who can see what
01
Named senior buyers per account
Each client account is worked by named senior media buyers assigned to it. You know who they are from kickoff, and access inside CurrentAds follows that assignment rather than being open to everyone on staff.
02
No offshore data resale
Your account data is not handed to offshore resale operations or anonymous outsourcing chains. The people with access to your account are the people working your account.
03
We do not sell or share client data
Your performance data, customer lists, and audiences are yours. We do not sell them, share them with other clients, pool them into products, or use them to advantage a competitor. White-label partners see only the accounts they bring us, never anyone else's.
Portal
Portal security, without the jargon
The live client portal holds your reporting and plans, so here is exactly how it is protected, in words that do not require an engineering degree.
01
Individual logins
Every user gets their own account. No shared team passwords floating around a group chat.
02
Hashed passwords
Passwords are stored as one-way hashes. We could not read your password if we wanted to, and neither could someone who stole the database.
03
Rate limited sign-in
Repeated failed login attempts get slowed and blocked, which is what shuts down password guessing attacks.
04
Sessions that expire
Logins do not last forever. Stale sessions time out, so a laptop left open at a coffee shop is a bounded problem, not a permanent one.
05
HTTPS everywhere
Every page and every request is encrypted in transit. There is no unencrypted version of the portal.
06
Security headers
The portal ships standard browser protections: content security policy, frame blocking, and strict transport rules that tell browsers to refuse insecure connections.
Leaving
Offboarding, same day
Every engagement is month to month, so the exit needs to be as clean as the entrance. When you leave:
- Our access is revoked the same day you end the engagement, and you can verify it yourself in each platform's partner settings
- You keep your ad accounts, audiences, pixels, pages, and creative, because they were always in your name
- You get a data export on request: campaign structures, performance history, and reporting
- No offboarding fees, no data export fees, no ransom for your own accounts
This is the same policy behind our 30 day guarantee: you should stay because it works, never because leaving is expensive.
Honesty
What we do not claim
We do not hold a SOC 2 certification, and we will not decorate this page with badges that imply otherwise. Plenty of agencies paste compliance logos they have no right to; we would rather tell you plainly what we do and let you judge it.
If your due diligence needs more than this page covers, ask. Send security questions to contact@currentads.net and a real person will answer them specifically, including questions from your IT team or a white-label partner's client.