Security
Last updated October 6, 2026
Agencies trust LossLoops with their clients' leads, revenue and ad accounts. Here is how we protect them.
Each agency's data is walled off
Isolation is enforced by the database itself, not only by application code. Every table holding client data has row-level security keyed to the agency and, where a user's access is limited, to the business. The application connects with a database role that cannot bypass those rules, and automated tests try to read across agencies on every change.
Read-only access to your accounts
We request the narrowest read-only permissions each provider offers. LossLoops never posts, edits campaigns, messages leads or changes settings. Disconnecting a source deletes its tokens immediately.
Encryption
- All traffic uses HTTPS with HSTS.
- Data is encrypted at rest by our database and hosting providers.
- Access tokens for connected services get a second layer of encryption with keys held in a managed key service, separate from the database.
Accounts and sign-in
- Passwords are checked against known breached passwords and stored only as strong hashes.
- Two-factor authentication and passkeys are available to everyone and required for agency admins.
- You can see and sign out your active sessions, and changing your password signs out all of them.
- Repeated failed sign-ins are slowed and challenged rather than locking the account, so no one can lock you out on purpose.
How the software is built
- Every change goes through a pull request and must pass automated tests, a dependency vulnerability audit and a secret scan before it ships.
- Production database credentials never reach the web servers; schema changes run in a separate, restricted release step.
- Pages carry a strict Content Security Policy and other protective headers.
- Logs and error reports exclude passwords, tokens and request bodies.
Reporting a vulnerability
If you believe you've found a security issue, email info@hitselectagency.com with the subject “Security report”. Please give us a reasonable chance to fix it before sharing it, and don't access other people's data while testing. We'll acknowledge reports within 3 business days.