GaaS legal
Security
Last updated: September 27, 2026
Company: Versaunt, Inc.
Address: Versaunt, Inc., The Coda, 756 W Peachtree St NW, Atlanta, GA 30308
Email: privacy@versaunt.com
How Versaunt, Inc. protects the data you trust GaaS with.
1. Our approach
GaaS connects to your ad accounts and works with your brand content, so we treat security as part of the product. Our CEO owns the security program, and it follows the SOC 2 Security criteria. We are not SOC 2 audited yet; this page describes what is in place today.
2. Where your data lives
- Our application servers run on Amazon Web Services in the United States.
- Our database, sign-in, and file storage run on Supabase, hosted on AWS in the United States.
- Our website and web app are served by Vercel.
- Production servers have no open remote-login port. Administrative access goes through AWS Systems Manager.
3. Encryption
- Data sent between your browser and GaaS is encrypted with TLS 1.2 or higher, and our site enforces HTTPS (HSTS).
- Our database and its backups are encrypted at rest with AES-256 by our database provider.
- Our application servers' disks and their backups are encrypted at rest.
- Payments are handled by Stripe. Card numbers never touch our servers.
4. Access control
- Every signed-in request to our API is checked against the user's session.
- Our servers check that the signed-in user belongs to a workspace before reading or changing its data. Workspaces have owner, admin, and member roles.
- Ad accounts connect through each platform's official OAuth sign-in. We never ask for your ad-platform password.
- Only a small number of engineers can reach production systems.
- Staff accounts on our cloud, code, database, hosting, payments, and email systems require two-factor authentication.
- Customer passwords are checked against known leaked passwords, and email sign-in codes expire within an hour.
5. The AI agent and your ad accounts
- By default, the agent asks for your approval in the product before it makes changes in your ad accounts, such as launching ads.
- Autonomous mode is off unless it is turned on for your specific account.
- Each call to Meta is checked on our servers to make sure it stays inside the ad account you connected.
- Content the agent reads from the web is treated as information, not as instructions.
6. AI providers and your data
GaaS does not train AI models on your data. We use AI models from the providers listed under Subprocessors through their business APIs, only to produce the work you ask for.
7. Monitoring
- Every administrative action in our AWS account is recorded with AWS CloudTrail.
- AWS GuardDuty continuously watches our cloud account for threats.
- We are alerted automatically if the service goes down.
8. Changes, reliability, and backups
- Code reaches production only through a protected main branch, and every change must pass automated checks, including a scan for leaked secrets.
- Automated alerts flag third-party code libraries with known vulnerabilities, and our database is kept current with security patches.
- Deploys run through an automated pipeline that uses short-lived cloud credentials, checks the new version's health, and rolls back automatically if it fails.
- Our database is backed up daily, and backups are kept for 7 days. Our application servers are also backed up daily.
9. Data retention and deletion
- While your account is active, we keep your data so the product keeps working.
- After an account is closed or deleted, its data is deleted within 90 days.
- Server and error logs are kept for 90 days. Security and audit logs are kept for 1 year.
- Billing and invoice records are kept for 7 years, as tax law requires.
- To ask us to delete your data, email privacy@versaunt.com. See our Privacy Policy for your rights.
10. Subprocessors
These companies process customer data on behalf of Versaunt, Inc.. Ad platforms you connect (Meta, Google, TikTok, Amazon, Shopify) receive data because you direct us to send it, under your own agreement with them.
- Amazon Web Services — Application servers and short-lived caching (United States)
- Supabase — Database, sign-in, and file storage (United States, hosted on AWS)
- Vercel — Website and web app hosting
- Microsoft Azure OpenAI — AI text models that power the agent
- Google Cloud (Vertex AI, Cloud Storage) — AI image, video, and text models
- OpenAI — AI image generation and voice
- ElevenLabs — AI voiceover for video ads
- Firecrawl — Reading the websites you ask us to analyze
- Apify — Finding public competitor ads
- Foreplay — Competitor ad research
- Brave Search — Web search for the agent
- Twilio — Voice calls
- Stripe — Payments and billing
- Resend — Transactional email
- Google Workspace — Company email and support requests
- PostHog — Product analytics and session replay (inputs masked)
- Linear — Tracking bug reports you send us
11. Reporting a security issue
If you find a security problem in GaaS, email privacy@versaunt.comwith "Security report" in the subject. We aim to reply within 3 business days.
Please give us a reasonable time to fix the issue before sharing it publicly, and do not access other customers' data, change data, or disrupt the service while testing. We will not take legal action against good-faith research that follows these rules.
12. Security documents
Our security policies, full vendor list, and completed security questionnaire are available to customers and prospects under NDA. Email privacy@versaunt.com to request them.
