Security

Security Overview

ArcPilot is designed to reduce risk when working with advertising account data, analytics workflows, recommendations, and customer-authorized platform connections.

Last updated: June 17, 2026

Controlled account workflows

ArcPilot scopes TikTok integration behavior to the workflows enabled for each customer and the permissions granted through authorization.

Material account changes, including campaign, ad group, ad, status, or budget changes, must be protected by advertiser approval, permission checks, and audit logging before production use.

Token handling

OAuth tokens are intended to be encrypted before persistence and accessed only by server-side services that need them to perform authorized API requests.

Access is scoped to the permissions granted by the advertiser and can be revoked by the advertiser.

Operational controls

ArcPilot records audit events for important user and system actions. Recommendations include evidence and confidence so users can review the reasoning before acting.

We avoid asking users to share TikTok passwords. Account connection should happen through official OAuth authorization flows.

Report a vulnerability

Please report security concerns to support@arcpilot.net with enough detail for us to investigate.