Built to be trusted withlive accounts.
Offloda operates on live ad spend and client data. The architecture assumes that responsibility everywhere — this page is the plain-language version of how.
Six guarantees, by construction.
OAuth-only connections
Platforms connect via OAuth — Offloda never sees or stores your passwords. Tokens are scoped to the access you grant and encrypted at rest.
Tenant isolation
Every client brand is an isolated workspace, enforced with row-level security at the database layer — one client's data is never visible to another.
Approval-gated writes
Nothing changes on a live account without explicit approval. High-risk actions need a second acknowledgement; new campaigns launch paused.
Hashed API keys
REST API keys are stored as one-way hashes — shown once at creation, revocable instantly, scoped per agency.
Immutable audit log
Every read and every write is recorded — who asked, what changed, and when it was approved.
No AI keys in the browser
All AI calls run server-side; your browser never holds a model key. Chat surfaces run on your own LLM subscription.
Least privilege, per seat.
Three roles
Owners manage the workspace, managers run operations, operators execute — each with exactly the permissions the role needs.
Brand scoping
A seat can be limited to specific client brands — the rest don't exist for them.
Platform scoping
Seats can also be limited per platform — an operator can hold Google Ads without ever touching Meta.
Security questions
Can Offloda — or the AI — spend money on its own?
No. Every budget or bid change is dry-run first and requires confirmation; new campaigns launch paused; high-risk actions need a second acknowledgement. The AI proposes, a human approves.
What data do you store?
Encrypted OAuth tokens, the performance data needed to render dashboards and reports, and the audit trail of actions. We never see platform passwords, and we don't sell or share tenant data.
Who on my team can see what?
Whatever you scope them to: roles control what a seat can do, and per-brand and per-platform grants control what it can see. Client portal seats are view-only by design.
How do I delete my data?
Disconnecting a platform removes its credentials and connected data. Meta users can also trigger deletion from their Facebook settings — see the data-deletion page for status lookups. For full account deletion, contact us and we'll confirm completion.
Have a question this page didn't answer?
Security review for your agency or franchise? We'll walk your team through it.