Your data stays protected, segregated, and under your control.
Tapper runs on Google Cloud in the EU with encryption in transit and at rest, tenant-scoped access to every record, and clear limits on what is collected, who can see it, and where it goes.
SOC 2 Type II-aligned controls
Our security program is designed to meet SOC 2 Type II requirements, and we maintain SOC 2-aligned policies and control procedures. Our cloud infrastructure is linked to Drata, a leading security and compliance platform.
Privacy-first data practices
Tapper acts as a processor under GDPR and a service provider under CCPA. Data is used solely for fraud detection and your own models, never sold or shared beyond the disclosed sub-processors.
Annual penetration testing
The platform is independently penetration tested each year, and the report is part of the security package.
Tenant segregation
Every record is tagged with your account ID, every API request is scoped to your tenant, and no cross-tenant read or write is possible at the application level.
Your data is scoped to your account, record by record.
Tapper uses the data you connect to protect and optimize your own campaigns, with each record tagged to your tenant ID and access enforced through row-level filtering.
No data selling
Customer data is not sold or shared beyond the disclosed sub-processors.
No pooled CRM data
Salesforce data lives in per-customer stores and is never pooled, so one customer's CRM outcomes never inform another customer's models.
Outputs go only to your ad accounts
Outputs go only to your own Google Ads and Meta accounts: IP exclusions, blocked audiences, and conversion values. Hashed emails and phones never leave Tapper.
You control the connections
You choose which sources connect, can pause or disconnect Salesforce at any time, and the monitoring script can come down within 30 days of written notice.
Designed to minimize data movement.
Approved sources
Your site's monitoring script, your ad account APIs, an MMP postback you already send, or a read-only Salesforce connection. No SDK, no code changes, and no access to your source code or your app.
Segregated processing in the EU
Data is processed on Google Cloud in europe-west1, encrypted with AES-256 at rest and TLS 1.2 or higher in transit, in tenant-scoped storage with row-level filtering on your account ID.
Approved outputs
Only the outputs you configure leave Tapper: IP exclusions and blocked audiences to your ad accounts, and conversion values with a click ID to Google Ads. No email, phone, hash, name or CRM content is sent.
Protection at every layer.
Encryption
TLS 1.2 or higher in transit, AES-256 at rest including backups, keys held in Google Cloud KMS, HSTS enabled.
Controlled access
Least privilege, unique accounts, no direct employee access to production data without explicit and temporary approval, public SSH disabled.
Authentication
Multi-factor authentication on accounts, single sign-on through centralized identity providers, automatic session lock.
Continuous review
Continuous monitoring and logging, automated vulnerability scans at least quarterly, a web application firewall, an annual independent penetration test and an annual risk assessment.
Everything your security team needs.
The full policy pack, the cookies disclosure and the Salesforce data disclosure are on the security, data and privacy report.
Common security questions.
No names, emails or financial data are collected by the monitoring script. It reads the signals a browser already sends with every request, such as IP address, user agent and click data, and uses them solely to tell genuine users from invalid traffic. Every input field is redacted before processing, and email and phone values from a CRM connection are hashed at ingest with the raw values never stored.
Every record is tagged with your account ID, every API request is scoped to your tenant, and backend services enforce row-level filtering, so no cross-tenant read or write is possible at the application level. Salesforce data sits in per-customer stores and is never pooled.
Your CRM data is not. Reporting and model training on your Salesforce data run against your own dataset, and Salesforce data is never pooled across customers, so one customer's outcomes never inform another customer's models. Invalid-traffic detection learns from click and session patterns, never from your customer records.
Only what you configure. Invalid IPs are added to your Google Ads exclusion list and to blocked audiences on Meta, and conversion values are uploaded to Google Ads with the click ID, value and currency, timestamp, order ID and consent flags where required. No email, phone, hash, name or CRM record content is sent, and nothing goes to any other third party.
The monitoring script can be removed within 30 days of written notice. Disconnecting Salesforce revokes the token and deletes the stored credentials. Data is retained for a default of 12 months, configurable per agreement, and on written instruction Tapper returns or securely deletes personal data and confirms it in writing under the DPA.
No. An MMP integration is a single webhook URL pasted into the MMP's callback settings, with no SDK change, no app release and no access to your source code or MMP account. Salesforce access is read-only, enforced by the permission set your admin assigns.
Ready for your security review?
Compliance materials, technical documentation and questionnaire support, with a direct line to the team that runs them.