AdSheriff connects to your ad accounts with the least access possible, never stores your passwords, and logs every single thing it does — reversibly. Here's exactly how.
You connect through Meta and Google's official OAuth 2.0 login. We never see or store your ad platform credentials — only a revocable, limited-scope access token stored in a dedicated secrets vault.
We request the absolute minimum scopes needed to audit and apply approved changes. No access to your personal profile, messages, or unrelated platform data.
Every action the agent proposes or takes is recorded with a timestamp and reason in your action log — and every single API change is reversible in one click.
On Pro, nothing happens without your explicit consent. On Autopilot, the agent only acts inside the strict guardrails you configure in your dashboard.
All data is encrypted via TLS 1.3 in transit and AES-256 at rest. Access tokens are hardware-encrypted and rotated automatically to minimize risk.
Your account data is used to serve you — not to train models for anyone else. We never sell or share it. Disconnect anytime to revoke access instantly.
Because every change is applied through the official ad platform APIs and recorded in your log, anything the agent does can be rolled back from your dashboard. If a fix doesn't sit right, hit Revertand it's undone in your account.
Found something? We want to hear it before anyone else does. Email security@adsheriff.co — we acknowledge reports within one business day and won't pursue good-faith researchers who follow responsible disclosure.
Need our security overview or a DPA for your team? Email security@adsheriff.co.
14 days free, no credit card. Disconnect anytime — access is revoked instantly.
Start free →