Roles, permissions and approvals
People get the access their job needs, and the person who proposes a change is never the only one who can release it.
Roles: viewer, analyst, approver, administrator One person proposes a change, another approves it Approval rules you set by client, platform and spend amount Single sign-on (SSO) on the Enterprise plan Every approval logged with who, when and why A tamper-proof change log
Every change across every platform lands in one log you can search and export — not in screenshots.
One log across Google, Meta, Amazon, TikTok, LinkedIn and Microsoft Each entry: who, what, when, before and after, and who approved it Each entry is sealed with a fingerprint of the one before it (SHA-256), so editing an old entry shows Export it for your finance team, your auditors or your clients Your data
Claresto only handles the data it needs: campaign settings, spend, conversions, changes, approvals and invoices.
Access limited to what the features you turn on need You can remove Claresto’s access from each platform at any time Your ad and CRM data is never used to train AI models or pooled with other customers’ data Retention you choose, by type of data Encrypted in transit and at rest; built around GDPR principles such as collecting only what’s needed Built to pass vendor security reviews
A security pack answers the questions security, finance and procurement teams ask first.
Security pack: how access works, the permissions we ask for, encryption and retention Data processing agreement (DPA) and sub-processor list, under NDA Controls mapped to what SOC 2 change-management and SOX IT reviews ask for — this is a mapping, not a certification; ask us for current audit status Cloudflare is our main infrastructure provider