Security & trust
Current posture, clearly bounded.
This page separates implemented controls from design principles and future commitments. It is not a certification, audit report, or warranty.
Posture last reviewed
July 23, 2026
Implemented today
Clerk authentication and authenticated sessions
Product authentication
July 23, 2026
Server-side advertising-platform credentials
Credentials stay out of client-side code
July 23, 2026
AES-256-GCM application-layer token protection
Sensitive token material
July 23, 2026
Organization-scoped authenticated query paths
Authenticated product data
July 23, 2026
Action-log receipts for material governance actions
Organization, actor, action, and timing context
July 23, 2026
Operational boundaries
WATCH means visibility and human review
Humans remain responsible for platform actions
July 23, 2026
LinkedIn Ads budget-risk visibility
No platform write actions
July 23, 2026
Campaign or budget write actions
Requires separate validation and Approval
July 23, 2026
Not yet claimed
Third-party security certification
No certification claim
July 23, 2026
Completed independent penetration test or audit
No completed-assessment claim
July 23, 2026
Production customer DPA commitments
Documented in applicable customer terms
July 23, 2026
Product posture
- Read and monitor before write: current ad-platform integration work is designed for permissioned reporting, pacing context, and manual review—not campaign optimization or automated spend changes.
- Client-approved budget truth remains separate from platform delivery settings.
- Humans remain responsible for approvals, escalations, and any action taken in an advertising platform.
- Public marketing infrastructure is kept separate from authenticated product and data services.
Security design principles
- Collect and retain only information needed for the disclosed workflow.
- Request the minimum external-platform permissions needed for approved read-only use cases.
- Use OAuth or other provider authorization flows instead of asking customers to share ad-platform passwords.
- Keep access tokens and confidential integration credentials out of client-side code and public logs.
- Use encrypted network connections for public and authenticated web traffic.
- Scope application data by organization and preserve audit context for material governance actions.
- Review higher-risk changes—including authentication, tenant isolation, database policy, credentials, and production configuration—under a stricter preflight and recovery process.
Controls implemented today
- Clerk manages product authentication and authenticated sessions.
- Advertising-platform credentials remain server-side, with sensitive token material protected using AES-256-GCM application-layer encryption.
- Product data access is scoped by organization in the application's authenticated query paths.
- Material budget-governance actions can produce action-log receipts that preserve organization, actor, action, and timing context.
Advertising-platform data
PacePilot’s intended integration use is budget governance: retrieving authorized account, campaign, spend, and pacing context so an agency can compare delivery with its own client-approved budget model. PacePilot does not need member social content, audience lists, private messages, or customer passwords for that use case.
Access depends on the permissions granted by the customer and the platform. Customers should connect only accounts they are authorized to manage and can revoke provider authorization through the applicable platform controls.
Website and waitlist data
The public website uses third-party hosting, measurement, and form services. Waitlist submissions should contain business contact and workflow information only. Do not submit credentials, access tokens, payment information, or sensitive client records. See the Privacy Policy for current website data practices.
Access, retention, and deletion
Access to non-public systems and data is intended to be limited to authorized operators and service providers with a business need. Retention should be tied to product operation, security, legal obligations, and customer instructions. Product-level deletion and retention commitments will be documented in the applicable beta or customer agreement before production use.
Security incidents and responsible reporting
Suspected incidents are evaluated for containment, investigation, recovery, and any notifications required by applicable law or agreement. Until a dedicated security mailbox or disclosure channel is published, use the waitlist form and begin the workflow-context field with “Security report.” Do not include exploit code, credentials, or sensitive customer data in the form.
What this page is not
This page is a transparent description of current posture and design principles, not a warranty, audit report, certification, data-processing agreement, or complete list of controls. It will be updated as PacePilot completes beta readiness, third-party assessments, and formal customer terms.
