Last reviewed: September 28, 2026.
This page describes practices that exist in MARKETIA's code and operations, not aspirations. When something changes materially, we update it.
Encryption in transit
- All traffic with MARKETIA (
marketia.cerebria.coandfapi.marketia.cerebria.co) and with this website is encrypted with TLS (HTTPS). - This website sends
Strict-Transport-Security(one year, withincludeSubDomains), so browsers never open it unencrypted. - Server calls to Meta, TikTok, Shopify and the other platforms always use HTTPS.
Encryption at rest
- Access tokens for connected accounts are stored encrypted. TikTok API for Business tokens use AES-256-GCM (256-bit key derived with HKDF-SHA256 and a random nonce per token). Meta, TikTok for Developers, Shopify and Dropi tokens use Fernet authenticated encryption (AES-128-CBC + HMAC-SHA256).
- The encryption key lives in a server environment variable, never in code or in the repository.
- Tokens are decrypted only on the server, at the moment of calling the platform. They are never returned to the interface or the API, nor written to logs, alerts or notifications.
- MARKETIA user passwords are stored only as bcrypt hashes.
Official OAuth and least privilege
- Each business connects its own accounts through each platform's official login. MARKETIA never asks for or sees social media passwords.
- OAuth flows carry a signed, short-lived
stateparameter (15 minutes for TikTok, 10 for Shopify) that binds the authorization to the organization and the person who started it, preventing CSRF. - We record which permissions each account granted. Every feature checks that it has the permission it needs before running; otherwise it is disabled with instructions to grant it. New permissions are only requested once the feature that uses them is ready.
- Each permission and what it is used for is listed on the integration pages.
Tenant isolation
- MARKETIA is multi-tenant: every query is filtered by the requester's organization. Requesting another organization's resource returns "not found", without revealing that it exists.
- An ad account (Meta or TikTok) or an active TikTok account can only be connected to one organization, so no business can see another's spend or metrics.
- Disconnecting an ad account purges its data; deleting an organization deletes everything it owns.
User accounts and roles
- Three roles: superadmin (platform operations), superowner (manages their organization: connects accounts, manages users) and owner (read-only access to their organization).
- Only a business's administrators can connect or disconnect accounts and see its settings.
- Sessions use short-lived signed tokens that are renewed; an invalid token ends the session.
Webhooks and outbound calls
- Incoming webhooks are verified before processing:
X-Hub-Signature-256for Meta (Facebook, Instagram, WhatsApp and Threads), HMAC for Shopify andTiktok-Signaturewith a maximum time skew for TikTok. - Events are stored in a durable inbox and processed idempotently.
- Deauthorization from a platform (for example TikTok's
authorization.removedor removal from Facebook) is always applied immediately.
Operations and logs
- Secrets (API keys, encryption keys, database credentials) are configured per environment and never stored in repositories.
- The code has automated tests and changes are made through pull requests.
- Limited retention: AI analyses are deleted after 90 days, technical logs of AI calls after 30 and error logs after 14.
- We do not sell data or use it for third-party advertising or to train AI models.
Providers
We only use the providers needed to deliver the service (hosting, AI, email, storage). Each one and what it receives, including the selectable AI providers and where their servers are, is in the privacy policy.
This website
- Security headers: a restrictive
Content-Security-Policy(own-domain resources and the contact form API,api.cerebria.co, only),X-Frame-Options: DENY,X-Content-Type-Options: nosniff,Referrer-Policy: strict-origin-when-cross-originand aPermissions-Policywith no camera, microphone or geolocation. - No cookies, third-party analytics or advertising pixels.
- The contact form limits how many messages can be sent from the same IP address, silently discards bot submissions (hidden honeypot field) and stores the IP only as a keyed HMAC-SHA256 hash, never in clear text. Browsers can only send it messages from this website (CORS). It sends an email notice of each message only if that notice is configured on the server.
Responsible disclosure
If you find a vulnerability in this website, in MARKETIA or its API, email developer@cerebria.co with the subject "Security". This is also published at /.well-known/security.txt.
What to include
- A description of the issue and its impact.
- Steps to reproduce (URL, request, test account used).
- How we can reach you if we need more detail.
Rules
- Use only your own accounts; do not access, modify or delete other people's data.
- No denial of service, spam, social engineering or physical testing.
- Give us reasonable time to fix it before making it public.
We will acknowledge receipt, keep you informed about the fix and, if you wish, credit you publicly. We will not take action against good-faith research that follows these rules.