Trust
Security and data handling
This page describes how the platform is built and what it does with your data. Where a control is planned rather than in place, it says so.
Access control
Every workspace is isolated, and access within a workspace is governed by roles. Permissions are enforced on the server for every request, not only in the interface, so a user cannot reach data their role does not allow by manipulating the client.
- Role-based permissions applied per workspace
- Server-side authorisation on every data access path
- Private application areas require authentication and are excluded from search indexing
Audit logging
Significant actions — campaign approval and rejection, audience changes, permission changes, integration authorisation — are written to an audit log with the acting user and a timestamp. The log is append-only from the application's perspective.
AI processing
AI features operate on the product, audience and campaign data in your workspace. The AI Copilot is permission-aware: it can only reference data the current user is allowed to see, and any action it proposes follows the same approval rules as a manual one.
Campaign drafts are never sent automatically. Human approval is a structural requirement of the workflow.
Customer data
We do not publish aggregate statistics, research or examples that could identify an individual customer or their contacts. Where we publish first-party research in future, it will be aggregated, anonymised and described with its methodology.
Integrations
Planned integrations will use scoped credentials granted by an administrator, request the narrowest access that makes the feature work, and be revocable from workspace settings at any time. Delivery integrations are designed to create drafts rather than send on your behalf.
Current status
Campiqo is an early-stage product. We do not claim any third-party security certification, and we will not list one until it has actually been awarded. If your organisation requires a security review before evaluation, contact hello@campiqo.com and we will answer directly.
Reporting a vulnerability
Report suspected vulnerabilities to hello@campiqo.com. Please include enough detail to reproduce the issue. We will acknowledge reports and will not pursue action against good-faith research.
See how Campiqo works on your own product
Paste a public product or business page and review the campaign it produces. No account is needed to generate your first campaign.