How we protect your data
Security isn't an afterthought at Agencica — it's built into how the platform is architected, from database-level tenant isolation to encrypted storage. Below is an overview of the safeguards in place. If you have specific security or compliance questions not covered here, reach out at support.agencica@gmail.com.
Every organization's data is isolated at the database level using row-level security (RLS) — not just application logic. One agency's account cannot access another agency's clients, tasks, files, or financial data, even in the event of an application-level bug.
All data is encrypted in transit using TLS/HTTPS, and encrypted at rest in our database and file storage.
Passwords are hashed using industry-standard algorithms and never stored in plain text. Optional Google Sign-In (OAuth 2.0) is available as an alternative to passwords.
Uploaded creative files are scoped per-organization at the storage layer, with access enforced by policy — not just by keeping a link private or hard to guess.
Our infrastructure runs on Supabase (backed by AWS) and Vercel, both of which maintain independent security certifications and regularly audited infrastructure.
Internal team access to customer data is limited to what's strictly necessary for support and operations, and is granted on a case-by-case basis rather than by default.
Our database provider performs automated backups as part of our hosting plan. We recommend agencies also maintain their own export of critical business records as a general best practice, independent of any platform they use.
In the event of a confirmed security incident affecting customer data, we will investigate promptly, take steps to contain and remediate the issue, and notify affected customers without undue delay, consistent with our legal obligations.
If you discover a security vulnerability, please report it to support.agencica@gmail.com rather than disclosing it publicly. We take all reports seriously and will respond as quickly as possible to investigate and address confirmed issues. We ask that you give us reasonable time to address a vulnerability before any public disclosure.