Security

Draft — last updated before launch, pending a full security review.

Read-only by design

Every platform connection (Meta, Google, TikTok, your store, Mailchimp) uses OAuth with read-only scopes. ROASted cannot post, spend, change settings, or take any action on your connected accounts — it can only read performance data to build your report.

Passwords

Your ROASted password is never stored in plain text. It’s hashed before it touches our database, so even we can’t see it.

Disconnecting access

You can disconnect any platform from your dashboard at any time, which revokes ROASted’s access on that platform’s side, not just in our records.

What we’re still hardening

We’re honest about where we are: ROASted is in early access, and encryption-at-rest for connected-account tokens is on our near-term roadmap rather than shipped today. If that’s a blocker for your account, email us before connecting anything sensitive and we’ll tell you exactly where things stand.

Report a concern

If you find a security issue, tell us directly rather than publicly: [email protected]. We’ll respond and credit you if you’d like once it’s resolved.