AES-256-GCM Encryption
All OAuth tokens are encrypted at rest using AES-256-GCM — the same standard used by banks and government agencies worldwide.
Zero Password Storage
Joiyn never sees, stores, or transmits your clients' passwords. We use OAuth — clients authenticate directly with Google and Meta.
GDPR + CCPA Compliant
Full compliance with GDPR and CCPA. Data processing agreements available. Right to erasure honoured within 30 days.
Data Isolation per Agency
Every agency's data is fully isolated. No cross-contamination, no shared databases, no accidental exposure between tenants.
TLS in Transit
All data in transit is encrypted using TLS 1.3. Every API call, every webhook, every token exchange is fully encrypted end-to-end.
Access Persists Independently
Client permissions are granted directly inside Google and Meta — not proxied through Joiyn. If we go down, your access stays.
DPA Available on Request
Need a Data Processing Agreement for your enterprise compliance? We provide signed DPAs to any agency that requests one.
Regular Security Audits
We conduct regular internal security audits and penetration testing to identify and address vulnerabilities proactively.