Security of AI advertising tools: how Phanes protects accounts, data and budget

A tool with access to your ad account has access to your budget. That is why Phanes security consists of eight layers that every piece of data and every decision passes through.

Phanes team7 min read
7 days of PRO free · no card

AI chats and agents with account access brought a new risk: a model that can change something in the account based on an instruction nobody checked. OWASP calls this Excessive Agency and recommends that a human approve high-impact actions. Phanes has followed this principle from day one.

AES-256-GCM
authenticated encryption of Google and Meta tokens
≥ 3 accounts
minimum for every cross-account conclusion, without names or identifiers
3,050
API fields in the validation catalog, and every change has a validation proof before the button
30 days
to undo a change executed by Phanes

Threat model: what can go wrong

Security starts with asking what specifically can fail. These are the six risks we take most seriously, and Phanes's answer to each.

Risk
How Phanes responds
A token leaks from the database.
The token is encrypted with AES-256-GCM. Without the key, which lives outside the database, the record is useless.
A token ends up in error logs.
Meta and Google tokens, API keys and Bearer headers are masked before writing.
One client's data shows up for another.
Database policies block outside access, and every query filters by account owner.
A hidden instruction in a web page or file (prompt injection).
The model has no tool that changes the account by itself. Every change is a card to approve.
A wrong decision on bad data.
The measurement verdict and the learning-phase gate stop recommendations before they reach you.
A change that went wrong.
Verification after execution, undo for 30 days and emergency switches for writes.

Eight layers of protection

  1. Sign-in

    You sign in with a Google account. The Meta connection is protected by a one-time key in an httpOnly cookie, which prevents request forgery.

  2. Token encryption

    Google and Meta tokens, cached API responses and chat notes are encrypted with AES-256-GCM. Without the encryption key, production refuses to store a token.

  3. Clean logs

    Meta and Google tokens, API keys and Bearer headers are stripped from every error before it is stored.

  4. Data isolation

    Database policies block direct access to every table. The application checks the account owner and the confirmed account selection on every query.

  5. Least privilege

    GA4 and Search Console are read-only. Write access only where Phanes executes approved changes.

  6. Learning privacy

    Cross-account conclusions only from at least 3 accounts and with no single account dominating (40% share at most). With too little data there is no conclusion at all.

  7. Own model, no access to keys

    Aether, the Phanes language model, receives computed facts: metrics, audit findings, knowledge excerpts. It gets no tokens, does not decide on changes and runs on Phanes infrastructure.

  8. Change control

    API dry run, diff preview, human approval, an account state re-check, verification after execution and 30 days to undo. Plus emergency switches for automation and writes.

Encryption: what we protect

AES-256-GCM is authenticated encryption: besides hiding the content, it detects any attempt to tamper with it. Every record gets a random 96-bit initialization vector, so two identical tokens look completely different in the database.

Initialization vector (IV)96 random bits drawn for every write. Two identical tokens produce two different records.
Authentication tag128 bits. Detects any change to the record: tampered ciphertext cannot be decrypted.
CiphertextThe encrypted content, such as an access token. Useless without the 256-bit key kept outside the database.
Anatomy of an encrypted record in Phanes: IV, tag and ciphertext stored together. The values in the graphic are examples.

We encrypt what gives access to your accounts and money: Google OAuth tokens, Meta and other platform tokens, cached API responses and chat notes. The encryption key is kept outside the database, in the server's environment variables.

Isolation: only you see your data

Phanes serves many companies and agencies, so data separation is built into every query rather than added at the end.

  • Outside access to tables is blocked by database policies on every table.
  • Every application query filters data by owner and confirmed account selection.
  • A shared analytics link is a frozen snapshot without tokens or account IDs, valid for up to 30 days and revocable.
  • Knowledge from other accounts reaches you only as an anonymized aggregate, never as a specific company's data.
  • All Phanes data, from the database to the language model, is stored and processed in the European Economic Area.

Aether: how we use AI, and how we do not

Phanes has its own language model, Aether. Its job is narrow: describe the engine's conclusions in plain language, answer in the chat with evidence and a rule citation, and classify search terms. It runs on Phanes infrastructure, so your account data does not go to external model vendors. It does not decide on changes and has no tool that changes anything in the account. Security is built into the training itself: the model is rewarded only for answers that pass automatic verifiers.

Numbers only from the data

Every number in an answer must appear in the input data, in the same currency. The model is penalized for every foreign number.

A valid schema

The answer passes structure validation before anyone sees it.

Clean language

The whole answer is in the dashboard language, Polish or English, never mixed.

No empty promises

The model never promises an execution the engine does not provide and never reveals knowledge sources.

Rule citation

A chat answer cites a rule that actually exists in the knowledge base.

Brevity

A penalty for verbosity: the answer must be short and concrete.

Training data is anonymized and passes the same privacy audit as the rest of Phanes. Facts do not go into the model's weights but into the knowledge base the model consults at question time. A new model version enters the product only after a test on a frozen task set, and is rejected if it performs worse.

A typical chat or agent with skills
Phanes
The model can call a write tool by itself if it has access to one.
A change from the chat is a card that waits for your click.
A skill is an instruction, and a malicious skill can push the model into unexpected actions.
Decisions come from coded rules, not from instructions loaded during a conversation.
A web page or file can carry hidden instructions (prompt injection).
Even a convincing instruction ends as a card to approve, not a change in the account.
The model computes metrics itself, with a risk of error.
The engine computes the numbers; Aether receives them ready and is penalized in training for any number outside the data.
The same request can lead to a different decision.
The same data leads to the same decision.

Safety of changes in the account

  1. Change limits

    A budget change above 20% requires extra caution, and a change above 100% in one step is blocked.

  2. Dry run

    Every change passes a write validator and a dry run in the Google or Meta API, without writing to the account. The button appears only with a validation proof.

  3. Preview and approval

    You see the diff and decide. At approval the account state is checked again.

  4. Safe defaults

    New campaigns are created paused by default. Phanes never permanently deletes campaigns, ad sets or ads.

  5. Verification

    After execution Phanes checks that the change actually went through.

  6. Undo and kill switches

    You can undo a change for 30 days. Emergency switches stop automation or all writes at once.

A change in the account: the diff, API validation and human approval.

What Phanes never does

  • It never knows or stores Google or Meta passwords.
  • It never stores tokens in plain text or in logs.
  • It never sends your account data to external model vendors and never stores facts about your account in its model's weights.
  • It does not execute budget changes without your approval.
  • It never permanently deletes campaigns, ad sets or ads.
  • It never shows your account data to other companies, only anonymized aggregates of at least 3 accounts.

GDPR and encryption

GDPR Article 32 explicitly lists encryption as a security measure for processing, and Article 28 requires processors to provide sufficient technical guarantees. Token encryption, data isolation and change control in Phanes are measures of exactly this kind.

Does Phanes know my Google or Meta password?

No. Phanes never knows passwords. It receives OAuth tokens, which are encrypted with AES-256-GCM and masked in logs.

Does my data reach an AI model?

Your data is handled by Phanes's own language model, Aether, which runs on Phanes infrastructure. It receives the computed facts needed to describe conclusions, without access tokens, and its training data is anonymized. Facts about your account do not go into the model's weights.

Will other companies see my data?

No. Data is isolated by owner. Cross-account knowledge reaches others only as an aggregate of at least 3 accounts, without names or identifiers.

Can Phanes spend my budget on its own?

No. Every budget change requires your approval after API validation and a diff preview. You can undo an executed change for 30 days.

Sources (5)