Enterprise-Grade Security
We handle millions in ad spend and sensitive customer data. Our architecture is built from the ground up to ensure strict isolation, encryption, and zero-trust access.
Workspace Isolation
Every database query is strictly scoped by Tenant ID. Glimmio enforces hard logical boundaries preventing any data leakage between brands or agencies.
Encrypted Credentials
OAuth tokens (Meta, Google, Shopify) are encrypted at rest using AES-256. Webhook payloads are cryptographically verified using HMAC signatures.
Role-Based Access Control
Glimmio supports 13 granular roles (from Owner to Client Viewer) mapped to an explicit 47-point permission matrix enforced entirely server-side.
Immutable Audit Logs
Every sensitive action—budget changes, role updates, and new API connections—is logged with actor ID, timestamp, and IP address for full accountability.
Integration Security
We operate strictly via official APIs (Meta Business Graph, Google Ads API, Shopify Admin API). We do not use scraping or unauthorized workarounds. All connections require explicit OAuth authorization. For detailed scopes, see our integration pages:
Incident Response & Reporting
If you believe you have discovered a security vulnerability, please contact our security team immediately at security@glimmio.com. We take all reports seriously and will respond within 24 hours.