Offloda.ai
Security

Built to be trusted withlive accounts.

Offloda operates on live ad spend and client data. The architecture assumes that responsibility everywhere — this page is the plain-language version of how.

The model

Six guarantees, by construction.

OAuth-only connections

Platforms connect via OAuth — Offloda never sees or stores your passwords. Tokens are scoped to the access you grant and encrypted at rest.

Tenant isolation

Every client brand is an isolated workspace, enforced with row-level security at the database layer — one client's data is never visible to another.

Approval-gated writes

Nothing changes on a live account without explicit approval. High-risk actions need a second acknowledgement; new campaigns launch paused.

Hashed API keys

REST API keys are stored as one-way hashes — shown once at creation, revocable instantly, scoped per agency.

Immutable audit log

Every read and every write is recorded — who asked, what changed, and when it was approved.

No AI keys in the browser

All AI calls run server-side; your browser never holds a model key. Chat surfaces run on your own LLM subscription.

Access control

Least privilege, per seat.

Three roles

Owners manage the workspace, managers run operations, operators execute — each with exactly the permissions the role needs.

Brand scoping

A seat can be limited to specific client brands — the rest don't exist for them.

Platform scoping

Seats can also be limited per platform — an operator can hold Google Ads without ever touching Meta.

Security questions

Can Offloda — or the AI — spend money on its own?

No. Every budget or bid change is dry-run first and requires confirmation; new campaigns launch paused; high-risk actions need a second acknowledgement. The AI proposes, a human approves.

What data do you store?

Encrypted OAuth tokens, the performance data needed to render dashboards and reports, and the audit trail of actions. We never see platform passwords, and we don't sell or share tenant data.

Who on my team can see what?

Whatever you scope them to: roles control what a seat can do, and per-brand and per-platform grants control what it can see. Client portal seats are view-only by design.

How do I delete my data?

Disconnecting a platform removes its credentials and connected data. Meta users can also trigger deletion from their Facebook settings — see the data-deletion page for status lookups. For full account deletion, contact us and we'll confirm completion.

Have a question this page didn't answer?

Security review for your agency or franchise? We'll walk your team through it.

AI-Power My Agency