AdvisorPPC

Security & Safety

Control every live change.

Your AI managers read and analyze authorized accounts through AdvisorPPC's server-side API, within your plan's usage allowance. You never connect a personal model-provider login. Manual asks before every write. Bounded Auto runs only when an admin or owner chooses it and only for eligible reversible changes inside account guardrails. Budget and bid changes always wait for explicit approval.

  • Manual by default
  • Spending caps that fail closed
  • Credentials encrypted at rest

How a change ships

Your managers prepare.
You decide.

  1. Read

    Your manager studies your account, your spend, and your results. Reading is always safe. It changes nothing.

  2. Stage

    When it finds an improvement, it prepares the exact change as a draft, a dry-run you can inspect line by line.

  3. Your yes

    Control

    Manual asks for your approval. Auto may continue only for an eligible reversible action inside guardrails you chose.

  4. Apply

    The action clears role, account and spending guardrails. Budget, bid and higher-risk changes still require your approval.

What is running today

Five safeguards, built in,
not bolted on.

Everything on this page is shipped and running now. Plain descriptions, no fine print.

Manual or bounded Auto

Manual asks before every write. When an admin or owner selects Auto, only eligible campaign status and negative keyword changes can continue inside the selected account guardrails.

Budget changes, bid changes, OAuth grants, billing and higher-risk changes always require explicit approval.

Spending guardrails that fail closed

Every write to an ad account passes a spend-cap check and a deny-by-default list before it runs. If a check cannot run, for any reason, the action is denied. When in doubt, the answer is no.

A broken safeguard stops the action. It never skips the check.

Your credentials, encrypted

The keys that connect your ad accounts are encrypted before they are stored, a separately sealed secret for each customer. They are never saved in plain text.

Fernet symmetric encryption, applied before anything reaches the database.

Refuses to start unsafe

If the service finds itself in an unsafe configuration, it refuses to boot rather than run with weak settings. Its database role also runs without superuser bypass, so even our own code has no shortcut around its limits.

Startup checks run before a single request is served.

Read-first managers

Every account manager reads and analyzes freely. Manual stages each write for review. Optional bounded Auto can apply only eligible campaign-status and negative-keyword actions inside selected-account guardrails.

Budgets, bids and higher-risk actions always wait for you.

The principle underneath

When a check cannot run,
the answer is no.

Many services fail open: if a safeguard breaks, actions slip through. AdvisorPPC fails closed. If the spend-cap check cannot run, the write is denied. If the configuration looks unsafe, the service will not start. A broken safeguard stops work. It never skips the check.

Straight answers

The questions owners ask us.

Can a manager spend my money on its own?
Bounded Auto can pause or enable a campaign inside the account guardrails you selected, which can change delivery. It cannot change budgets or bids. Those always wait for explicit approval, and a failed cap check denies the action.
Can it publish or send something without me?
No. Publishing, sending, OAuth grants, billing and higher-risk account changes require explicit approval. Bounded Auto currently covers only eligible campaign status and negative keyword changes.
How are my account credentials stored?
Encrypted, per customer, before they reach the database. Never in plain text.
Do you promise zero risk?
No, nobody honestly can. What we build instead is a set of safeguards that fail closed: when something is uncertain, work stops and waits for you.

See your managers work,
read-only first.

Connect an account and watch them analyze it. Free stays read-only. On paid plans, Manual stays the default.

Questions about security? Write to hello@advisorppc.com.