Skip to content
Legal

Security

What we do to protect the data our customers process through Convultra, stated plainly. We do not claim certifications we do not hold.

Last updated September 2026

1. Personal data is hashed before it leaves

Customer match data (email, phone, name, address) that a customer's site hands to Convultra for enhanced conversions is hashed with SHA-256 before it is transmitted to any advertising platform. Ad platforms receive hashes, never plaintext.

2. Encryption

All data is encrypted in transit with TLS. Data at rest, including stored credentials for connected ad platforms, is encrypted. Platform credentials are never returned by any API or shown in the dashboard after connection.

3. Access control

Access to a project follows one rule, applied identically in the database and the application: a superadmin, the account that owns the project, a team member of that account or project, or an agency with an active client relationship. Roles are owner, admin, member and viewer; viewers are read-only. API keys belong to an account or an agency, never to a person, are stored only as a hash, and can be restricted to named projects and scopes.

4. The public API and MCP server

The REST API and MCP server never return IP addresses, user agents, device fingerprints, coordinates, end-user identifiers, raw platform error text or any credential. URLs are reduced to paths. Geography rows below five sessions are suppressed. Redaction is enforced centrally and tested.

5. Hosting

Convultra runs on Vercel, AWS and Supabase, with analytics storage on Tinybird. Infrastructure is managed with least-privilege access. Production changes go through code review and automated tests.

6. Consent

The tracking script respects consent: when a visitor declines tracking, nothing is recorded or forwarded.

7. Reporting a vulnerability

Email security@convultra.com. We acknowledge reports promptly, keep you informed while we fix the issue, and do not take legal action against good-faith research that avoids privacy violations, data destruction and service disruption.

8. Certifications

Convultra does not currently hold SOC 2 or ISO 27001 certification. If your procurement process requires a specific certification, tell us at security@convultra.com and we will tell you honestly where we are.

Questions about any of this Our data protection contact is privacy@convultra.com. Security questions go to security@convultra.com.