SECURITY & DATA

Your accounts. Your data. Your approvals.

Zensifi.AI operates inside the video ad accounts you already own, with the narrowest access that can do the job, and nothing changes without a control you set.

Read-only until you approve

We start with read-only access to video campaign, delivery, and billing data across YouTube, social video and CTV. Write access, changing bids, budgets, or targeting, is granted per account and can be revoked by you at any time from the platform itself.

Human-in-the-loop changes

Our AI's optimization actions can run in recommend-only mode, where every change waits for your approval, or in autopilot inside guardrails you define. You choose per campaign.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Platform credentials are stored as scoped OAuth tokens in an isolated secret store, never as passwords, never in plaintext.

Least-privilege access

Access is role-based and scoped to the accounts a person works on, with SSO, enforced MFA, and audit logging on every internal action.

Minimal data, clear retention

We ingest video campaign, auction, delivery, and cost data across audience, inventory and creative signals. We do not need or request customer PII to produce savings. Operational data is retained for the term plus 12 months, then deleted on request within 30 days.

Contractual protections

A Data Processing Addendum is available and covers GDPR and CCPA obligations, sub-processor disclosure, breach notification timelines, and deletion on termination. Your data is never sold, and never used to train models for other customers.

Questions security teams ask first

Do you ever move money or change budgets without approval?

No. Budget-level changes always require explicit approval unless you enable autopilot with a spend guardrail, which caps what can change and by how much.

Is our performance data pooled with other advertisers?

Aggregate, de-identified auction-price signals inform benchmarks. Your account-level performance, creative, and audience data stay isolated to your workspace.

What is your compliance posture?

We operate to SOC 2 Type II control practices and are progressing through formal certification. Current control documentation and the DPA are available under NDA, ask on the demo call.

Bring your security reviewer, we'll answer live.