Trust

Security
and controls.

You never give us a password

Adalyst never asks for your login to any advertising or CRM platform. You approve the connection on LinkedIn, Google or HubSpot itself, and they hand us a key that you can withdraw at any time. We encrypt that key with AES-256-GCM before we store it, and swap it for a fresh one using each platform’s own refresh process.

Your workspace is your own

Everything we hold for you sits inside your workspace: your platform data, your CRM records, your account settings. Nothing crosses between workspaces. Inside your workspace, what each person can see and do depends on the role you gave them.

Sign in with your existing account

You can sign in through Google or Microsoft on every plan, so there is no extra password to look after. Your session is held in a cookie that is signed, so it cannot be forged, and that scripts running in the page cannot read. Every sign-in, and every action that changes the account, is written to a log you can read back.

Keeping your data separate from everyone else’s

Your data belongs to your workspace and to nothing else. Every record we store is stamped with the workspace it belongs to, and every read and every write checks that stamp before it hands anything back or changes anything. That check runs on our servers, so nothing happening in a browser can talk its way past it.

Encryption

Everything travelling between you and Adalyst is encrypted on the way (TLS 1.2 or higher). Three things are then encrypted a second time, by Adalyst itself, before they ever reach our database: the keys that connect your advertising and CRM platforms, the text we send to and receive from the AI models, and any AI provider key your workspace supplies. That second layer uses AES-256-GCM. The AI text and your own provider keys are locked with a key belonging to your workspace alone, and that key is itself locked inside a separate master key held apart from it. One of those categories being exposed does not open the other.

A record of every AI call we make for you

Each time Adalyst sends something to an AI model on your behalf we write down what happened: which model, which provider, how much text went in and came back, how long it took and whether it worked. The text itself is kept too, encrypted with your workspace’s own key. Before anything leaves for a model we scan it for patterns that look like sensitive information. Your admins can read the whole history, and there is a view-only role for anyone who needs to inspect the record, an internal reviewer or an auditor, without being able to touch the account.

Changes to your ad accounts

Nothing is written to a connected advertising platform until a person confirms it. At the moment you confirm, Adalyst records exactly what you approved: the change itself, the connection it was approved under, and the current state of every campaign, ad or form it will touch. Immediately before the change is sent, we check all of that again. If the connection has been re-authorised, an account has been switched off, or something has moved on the platform since you looked at it, we refuse the change rather than apply it to something you did not see. Approvals expire. Every change we send carries a tag of its own, so if we have to send it again the platform recognises it as the same change and will not create a second one. And if a change comes back with an outcome we cannot read, we never quietly retry it.

Where your data lives

Adalyst runs on established cloud providers. We handle your data under UK GDPR and EU GDPR, and where data moves outside the UK or the European Economic Area we apply further technical protections.

Keeping it, taking it with you, deleting it

You do not have to email us to leave. A workspace admin can export the entire workspace and schedule its deletion from Settings. Deletion waits 30 days, and you can call it off at any point in that window. After that it is permanent. Records of AI calls are kept for 400 days by default, and we can set that anywhere between 30 days and 7 years if you ask. Everything else, your platform data, anything you have uploaded, your briefings, has its own window, and they are all listed in the privacy policy.

Sub-processors

Adalyst relies on a short list of other companies to host, secure, deliver and run the service. We publish that list in full, with what each one does for us, what data it touches and where it processes it, so your security team can keep track of them alongside every other supplier.

Workspace admins can ask to be emailed whenever the list changes, under Settings → Organisation. If your team would rather watch it automatically, the same list is published as a feed at /api/public/sub-processors.

See the full sub-processor list →

Incident response

If we confirm a security incident that affects you, we will email your workspace admins within 72 hours, at the administrator addresses we hold. The notice says how serious it is, when we found it, and what we know so far.

That notice goes out whatever your email preferences say.

Contact: security@adalyst.app.

Responsible disclosure

Found a weakness in Adalyst? Email security@adalyst.app with the steps to reproduce it, the page or request it affects, and anything else that helps us see what you saw. The full policy lives at /.well-known/security.txt.

Connect your accounts today.

Start freeCancel anytime.