Omesta
How it worksAd creationReviewsPricingCase studies
Log inGet started
How it worksAd creationReviewsPricingCase studiesLog inGet started

Security & trustSecurity & trust

Your data.
Your controls.

Understand the permissions, safeguards and access controls behind your connected advertising accounts.

Explore the controls

Read the data disclosure

OMESTA / security

Clear boundaries.

Explore an explanatory permission model. Review the published specifications below.

An explanatory permission model

Reading a report ≠
changing a campaign.

Authorized connection
Available reporting fields
Workspace access
Review actual platform disclosures
Permission comes first.
Understand the boundary before connecting
  1. 01Scope.
  2. 02Control.
  3. 03Review.

Scope.

Access

The right scope for the job.

  • 01Review requested fields
  • 02Check platform permissions
  • 03Confirm the account
Keep the context.

Review the requested access for each integration. Reading a report and changing a campaign are different permissions.

Know what you authorize.

Control.

Changes

Choose how automation acts.

  • 01Enable supported rules
  • 02Review approval settings
  • 03Set budget limits
Keep the context.

Supported campaign changes depend on the permissions and controls enabled for your account.

Your settings matter.

Review.

Oversight

Keep the questions visible.

  • 01Review published disclosures
  • 02Check activity history
  • 03Request documentation
Keep the context.

Ask the team for the documents and account-specific details you need for your security review.

Go beyond an overview.

The foundations

Built around clear boundaries.

Review the published security specifications and the permissions requested by each platform before connecting.
01

Scoped OAuth

Review each platform’s authorization screen. Some integrations request broad scopes; actual reads and writes depend on the feature and account configuration.

02

Deployment-specific safeguards

Ask for the storage, transport, backup and access-control evidence relevant to your deployment. This page does not certify encryption settings or per-customer keys.

03

Activity records

Supported workflows record activity for review. Coverage and retention vary; this is not a guarantee of an immutable log of every action.

04

Payment-provider boundaries

Stripe handles subscription payment collection. Connected payment metadata is separate from card collection. A provider’s certification does not certify Omesta or remove our own obligations.

A connection with defined permissions.

Review the scopes for every integration. Supported campaign actions depend on platform permissions and the controls enabled for your account.

See the field-level disclosure

Connection review

Stripe

  • Omesta subscription billingSeparate from customer-connected accounts
  • Connected transaction signalsReview feature-specific data access
  • Granted API scopesReview the provider’s authorization screen

Meta Ads

  • Campaign reportingUses the connected account’s permissions
  • Supported campaign changesReview enabled automation and approval settings
  • Conversion and audience transfersSeparate data-use and consent requirements

Architecture

Understand how data moves.

This simplified flow is an explanation, not a security certification. Review actual permissions, transfers and deployment evidence.
Published data-flow overview
  1. 01Your platforms
  2. 02Authorized connection
  3. 03Omesta processing
  4. 04Stored records
  5. 05Dashboard
Review areaEvidence to request
Storage and backup safeguardsRequest deployed configuration and provider evidence
Transport securityReview the relevant endpoints and provider configuration
Keys and privileged accessRequest the applicable access and key-management details
Retention and deletionAgree the scope and deadlines; disconnect is not erasure

Access & oversight

Know who can do what.

Access, revocation and oversight are part of the same conversation. Review these commitments with the team when evaluating Omesta for your organization.
01

Dashboard and AI access

Team roles, AI tools and expressly agreed human ad management have different access needs. Review permissions and provider context for enabled features. A preview approval card or workspace switcher is not evidence of deployed authorization or tenant isolation.

02

Creative jobs and usage controls

The new production-credit wallet, top-ups, auto-refill and media pipeline are planned. Payment authorization, spending caps, duplicate-job handling, file access and provider deletion require implementation and testing before launch; this page does not certify those controls as live.

03

Different paths, different controls

Campaign automation, conversion forwarding and audience uploads are separate workflows. Account connection is not an individual’s advertising consent. Reversal of a change or transfer is not guaranteed.

04

Disconnect and delete are different

Review connection controls and revoke access with the source platform when needed. Disconnecting does not itself erase historical records or copies already sent elsewhere.

05

Customer access boundaries

Customer-scoped access and privileged support access need separate review. We do not claim a dedicated database for each customer or an absence of administrative access.

06

Evidence, not badges

Ask which independent reports, if any, are available and which entity and service they cover. We do not claim an Omesta SOC 2 report or ISO certification on this page.

07

European processing requires preparation

A DPA draft is not an executed agreement or proof of GDPR compliance. Required controls, provider terms and transfer arrangements must be verified before covered processing. EU-only residency is not promised.

08

Security questions and reports

Contact support@omestasystems.com for a security review or to report a concern. Do not include passwords, API keys or unnecessary personal data in your report.

Documentation

Go deeper than the overview.

Request available evidence from the team. This page does not assert certification, completed testing or that all privacy requirements have been met.

Independent audits

No Omesta certification or audit report is asserted here

Privacy obligations

Depend on processing, jurisdiction and implemented controls

Processing agreements

Require review and execution before covered processing

Request security documents ↗

Documentation

  • Integration Data Disclosure

    Review supported sources, data categories and feature-specific transfers.

  • Processing agreement review

    Request the status of the DPA and any required international-transfer arrangements.

  • Security evidence request

    Ask for available, current evidence. No completed penetration test is asserted here.

Security is a conversation.
Let’s have it.

Talk to the team

Product

  • How it works
  • Ad creation
  • Pricing
  • Reviews
  • Integrations

Solutions

  • Local businesses
  • E-commerce
  • Marketing agencies
  • Growth teams
  • Multi-brand

Resources

  • Blog
  • Case studies
  • Compare
  • Glossary
  • Help center
  • Changelog

Company

  • About
  • Careers
  • Partners
  • Press
  • Security
  • Contact
  • Privacy
  • Terms
  • Refund policy
  • Data disclosure
  • System status

© 2026 Omesta Systems.