Six concrete safeguards
- Hosted in the European Union. The database, background processing and files are hosted in Amsterdam (Netherlands), backups included.
- Agencies isolated in the database. PostgreSQL Row-Level Security: every query is filtered by the database itself. An agency cannot read another agency's data, even if there is a bug in the application code.
- Ad platform tokens encrypted. Meta, Google, Canva and Google Drive access tokens are encrypted with AES-256-GCM before being stored. They are never displayed in the interface.
- Two-factor authentication. One-time code (TOTP) from your authenticator app. Mandatory for agency administrators, available to everyone.
- Audit log. Logins, connection or disconnection of an ad account, bulk publishing, role changes, exports: every sensitive action is recorded with its author.
- Private files, 5-minute links. Creatives, brand kits and PDFs are kept in private storage. They are only served through signed links valid for 5 minutes, never through a public address.
Isolation
An agency cannot see another agency's data, and neither can a client. Most software filters data in its code. Kapitaine does too, but above all in the database itself, thanks to PostgreSQL Row-Level Security.
- Every database connection carries the identity of the agency and the user. The database only returns the rows that belong to them.
- A team member only sees the clients they are assigned to.
- An end client only sees their own campaigns, reports, creatives and invoices.
- If a query forgets a filter, the database returns zero rows rather than someone else's data.
Traceability
Every sensitive action leaves a trace, including support actions. When our support team needs to log in “as” a user to help you, the log records the real identity of the person acting, not just the account used.
- Log kept by the platform and retained for 24 months.
- When your agency opens a client's space (“view as client”), it is read-only, and the access is logged.
- Sessions limited to 12 hours.
- Actions recorded: logins, “log in as”, ad accounts connected or disconnected, bulk publishing, budgets, report publication, exports, role changes.
Access to ad platforms: only the permissions needed
Where a read-only permission exists, that is the one we request. You can revoke each access at any time, from Kapitaine or from the ad platform.
- Google Drive (read-only): drive.file permission. Kapitaine only accesses the images and videos you choose in Google's picker window (drive.readonly only with your agency's own Google Cloud project). It does not modify or delete your files.
- Canva (read-only): reading your designs and their information, to export them as PNG into the client's library.
- Google Ads (used for reading): Google does not offer a read-only Google Ads permission. Kapitaine uses it solely to read campaigns and results: no changes are sent to your Google Ads accounts today.
- Meta Ads (ads management): bulk publishing requires the ads_management permission. Every ad is created paused: nothing runs without your approval, and every publication is logged.
GDPR: your rights and your clients' rights
For your clients' data, your agency is the data controller and Kapitaine acts as a processor. For your agency account and this website, Kapitaine is the data controller.
- Record of processing activities kept up to date, with purposes, legal bases and retention periods.
- Full export of your agency's data in JSON format, in one click from Settings › Data (administrators only, recorded in the audit log).
- Permanent deletion on request: immediate purge from the database, purge from backups within 30 days, recorded in the audit log.
- No custom audience (list of individuals) is stored.
- No advertising tracker or audience measurement tool in the app: only a session cookie.
Details are in the privacy policy and on the data deletion page.
Subprocessors: who hosts what
The complete list of providers that process data to operate Kapitaine.
| Subprocessor | Role | Location |
|---|---|---|
| Railway Corporation | Database, background processing (synchronization, alerts, reports) and file storage | EU West region (Amsterdam, Netherlands) |
| Vercel Inc. | Hosting of the kapitaine.com website and of the application's web interface | Vercel's global network; company established in the United States |
| Anthropic, PBC (Claude API) | AI-assisted drafting of report commentary drafts and weekly summaries, based on aggregated campaign figures | Company established in the United States |
| Transactional email provider (selection in progress) | Sending of transactional emails (invitations, alerts, report notifications) | European Union (selection criterion); its name will be published here as soon as it goes live |
Found a vulnerability or have a security question?
Write to us at contact@kapitaine.com with the subject “Security”. Describe what you observed; please do not access other users' data or disrupt the service while carrying out your checks.