Autonomy you can hand over safely.
Giving a system write access to your ad accounts is a real decision. So the boundaries are technical, the access is scoped, and the guardrails are enforced by the engine - not left to good intentions.
Ad account access, scoped
RYAFR requests only the permissions it needs to launch, optimise and report on the accounts you connect. Read access comes first; write access is what you choose to grant, and you can revoke it from your platform at any time.
Encryption in transit and at rest
Data moving between RYAFR and the ad platforms is encrypted in transit, and stored data is encrypted at rest. Access tokens are never held in plain text.
Guardrails as hard limits
Your caps, brand rules and approval thresholds are enforced by the engine itself. Autopilot cannot spend past a cap or push a change above your threshold - the limit is in the code, not the policy.
It cannot cross a line you have drawn.
This is the difference between automation you have to watch and autonomy you can trust. The guardrails are not advisory. They are the outer edge of what the engine is able to do.
Stated honestly, as it stands today.
RYAFR operates on encryption in transit and at rest, scoped and revocable platform access, and guardrails enforced in the engine. We describe our posture as it actually is, and we do not claim certifications we do not hold. As our formal compliance programme matures, this page is where the current status will be stated - clearly and without overclaiming.
If your team has specific security or data-handling requirements, the fastest path is a direct conversation. We will tell you plainly what we do and do not yet support.
Have a security question before you connect?
Talk to us directly. We will answer plainly about access, encryption and guardrails.