Built so nothing changes on a live ad account by accident.
Loomstrat's approach to security starts with the workflow: gated portal access, reversible automation, and no payment data ever touching the platform.
No shared passwords for client access
Client-facing portal access uses email-gated magic links with verification codes, not a shared username and password. A client requests access with their email, verifies with a one-time code, and gets a session cookie scoped to their own workspace — nothing to leak, reuse, or hand off between team members.
Automation that never surprises you
Every automation rule supports dry-run mode, so you can see exactly what a rule would have done before it touches a live ad account. Rules that are allowed to act can require manual approval, and every executed change — automatic or approved — is written to a full audit log you can review at any time.
Campaigns never go live without confirmation
The campaign builder never pushes a new campaign live on its own. Every campaign you build in Loomstrat requires an explicit confirmation step before it launches on the connected ad account, so nothing spends budget without a human deciding it should.
No payment processing in billing
The billing module tracks invoice status — draft, sent, paid, void — and generates printable invoices per client. It does not process payments, store card numbers, or move money, which keeps payment-card data out of the platform entirely.
Verified ownership for custom domains
White-label client portals on a custom domain are only activated after you prove ownership of that domain with a DNS TXT record check, preventing a portal from being pointed at a domain you don't control.
Have a security questionnaire or a specific compliance question?
Compliance documentation is available on request. Reach out through the contact page and the team will get you what you need.
Have a question about how Loomstrat handles your data?
The team can walk through architecture, access controls, and automation safety in detail.