Every TrackOfferz customer gets the same security posture — encryption, audit trails, PII handling — regardless of plan.
Six security pillars covering the lifecycle from click ingestion to payout dispatch.
TLS 1.3 in transit, AES-256 at rest. All Postgres + ClickHouse + Redis volumes encrypted.
argon2id password hashing, Redis-backed sessions with instant revocation, OAuth SSO on the roadmap.
Outbound postbacks hash email + phone before dispatch when configured. Meta/TikTok CAPI integrations follow their hashing requirements out of the box.
Append-only audit table records every privileged action — admin overrides, impersonation, payout fires, manual replays.
Every table tenant-scoped by org_id. Updates + deletes enforced with row-level predicates server-side.
Edge tracking on Cloudflare. Origin services on hardened VPS with WireGuard mesh + firewall rules.
Reach out — we'll get you our SOC 2 status, DPA template, and any other docs you need.