← All legal documents

Last updated: 1 October 2026

Data Security

How your data is protected in CiroFly — encryption, access, and operational security.

Our security approach

CiroFly is a B2B platform that processes agency and brand performance data. Security is addressed from the design stage through access control, encryption, and operational discipline.

The measures summarized below describe the general framework; technical details are not disclosed publicly for security reasons.

Access control

The platform uses multi-layered authorization:

  • Agency, client, and administrator roles — each user sees only the brands assigned to them.
  • Row-level access rules at the database level (RLS).
  • Administrative and integration operations are restricted to privileged roles.

Authentication

Sessions are managed through a secure authentication infrastructure. Passwords are never stored in plain text.

Password resets are performed via e-mail verification; session information is stored securely in the browser.

Protection of integration credentials

Access keys stored for advertising and store connections are kept in encrypted form. Only the server components that perform data synchronization can access these credentials; raw tokens are never displayed in the panel interface.

Production environment keys are never included in source code or on the client side.

Network and infrastructure

Panel and API traffic is transmitted over HTTPS. Database and hosting services are kept with trusted cloud providers.

Regular backups and access logs are part of our operational processes.

Client data isolation

Each brand's performance data is segregated by brand name and user assignment. One client's data cannot be viewed by another account without authorization.

Agencies access only the client companies in their portfolio or those they have added themselves.

Incident response

In case of a suspected security incident, the relevant systems are examined, the impact is contained, and legal notification obligations are assessed.

To report a security vulnerability: info@cirofly.com

What you can do

Recommendations for your account security:

  • Use a strong and unique password.
  • Use the “keep me signed in” option carefully on shared computers.
  • Remove panel access for former employees.
  • Share integration keys only with trusted team members.