Security

Built for finance-grade trust

Creator programs touch payouts, PII and ad accounts. Here's how we protect all three.

Tenant isolation

Every record is scoped to an organization and enforced at the database layer with row-level security, so one workspace can never read another's data — even through the API.

Role-based access control

Owners, admins, affiliate managers, ads managers, finance managers, analysts and creators each receive a distinct permission set. Permissions can be extended or revoked per member.

Sensitive data handling

Shipping addresses, payout details and integration credentials are stored in restricted tables that application code cannot read without elevated server-side privileges.

Encryption

All traffic is served over TLS, and data is encrypted at rest in managed cloud infrastructure.

Audit logging

Permission changes, commission adjustments and statement approvals are recorded with actor, timestamp and previous value for finance-grade traceability.

Reporting a vulnerability

If you believe you've found a security issue, contact our team directly. We investigate every report and will confirm receipt promptly.