Security

Security for a system that can spend money.

ROI.me will hold advertising credentials, CRM data and the ability to change live campaigns. This page describes the controls that protect them. It describes architecture, not a certification.

Pre-release

ROI.me is in development and not yet processing customer data. The controls below are the security architecture we're building to; each will be in place before the capability it protects goes live. We'll keep this page current as that happens.

Certifications

ROI.me does not currently hold SOC 2, ISO 27001 or HIPAA certification, and isn't designed to process protected health information. We'll update this page if that changes. Enterprise customers can request our current security documentation through contact.

Tenant isolation

  • Every record belongs to an organization, and every service call is scoped to the caller's organization.
  • An automated test will fail the build if any tenant data table is missing an organization reference.
  • Public identifiers are random and prefixed; internal database IDs are never exposed.

Credentials and secrets

  • Ad-network and CRM OAuth tokens are encrypted at rest with AES-256-GCM using versioned keys that can be rotated.
  • API keys are shown once at creation and stored only as a hash.
  • Webhook payloads are signed with a per-endpoint secret (HMAC-SHA256) and a timestamp to prevent replay.
  • Secrets are never logged; request logs redact authorization headers and cookies.

Access control

  • Six roles (Owner, Admin, Marketer, Analyst, Developer, Viewer) with permissions enforced on the server, not by hiding buttons.
  • API keys carry explicit scopes and can never exceed the permissions of the person who created them.
  • The MCP server and ROI Agent use the same permission checks as the portal.

Controls on spend

  • Launching campaigns, increasing spend, deleting data and disconnecting integrations require approval by default.
  • Autonomy is opt-in per organization, with maximum daily, monthly and per-campaign spend limits.
  • ROI Agent has no direct database access; it uses typed, permission-checked tools.
  • An administrative emergency stop halts all spend-affecting actions platform-wide.

Audit logs

Actions that affect live campaigns, spend, permissions, credentials or data are recorded with the actor (a person, API key, MCP client or the agent), the action, the target, the before and after state, the time and the request ID.

Data handling

  • The ROI Pixel doesn't collect form field contents or passwords, and respects the consent state on your site.
  • Identifiers such as email and phone used for audience matching are normalized and hashed before they're sent to ad networks.
  • The website crawler used by Brand Brain fetches only public pages, blocks private network addresses and follows robots rules.
  • High-volume event data is stored separately from transactional data.

Reporting a vulnerability

If you believe you've found a security issue, please email [email protected] with details and steps to reproduce. Please don't access data that isn't yours or disrupt the service while testing.