Cortex reads from the tools you already run — ad platforms, your CRM, and your accounting books through Margin — to show attribution, MER, blended CAC, and your actual P&L in one place. This page is for the buyer whose finance or security team will ask exactly what that means: what we store, how it is protected, who else touches it, and how to get it deleted.
One commitment up front: we never sell your data. It is used to run the product for your organization, and nothing else.
Every connection is authorized by you over OAuth, and each source stores only what the reports and marts need.
Meta, Google, LinkedIn, TikTok, Microsoft, Pinterest, Reddit, and Criteo connect over OAuth. Cortex reads campaign structure and reporting metrics — spend, impressions, clicks, and conversions — at the account, campaign, ad-set, and ad grain. It does not post, pause, or change anything in your ad accounts.
HubSpot, Salesforce, and ActiveCampaign sync deals, companies, campaigns, and pipeline stages. Person-level contact fields — names, phone numbers, mailing addresses — are blocked at the connector, so they never land in our warehouse in the first place. Email is retained only where it is needed to match a person across your own sources for attribution; internal staff records (deal and contact owners) are treated as company data, not customer PII.
Margin connects QuickBooks Online or Xero as a read-only sync — data flows out to Cortex, never back to your ledger. It stores the summary lines needed to build a monthly P&L and to join marketing to the books: revenue, expense accounts, and first-sale dates that drive MER and blended CAC. It does not create, edit, or pay anything in your accounting system.
Data is encrypted in transit over TLS, and encrypted at rest by the managed platforms it lives on: the application database runs on managed Postgres at Supabase, and the analytics warehouse runs on BigQuery in Google Cloud.
Access is scoped to your organization. Row-level security policies keep each organization’s rows separate at the database, and role-based access control governs what each member can do. New members who join by matching your email domain land as Viewer by default; admins assign Admin, Editor, or Viewer roles from the settings screen.
The credentials that reach your connected services are held as managed secrets in Google Cloud Secret Manager, read through a single server-side helper. They are never exposed to the browser or checked into source.
Cortex relies on a short list of sub-processors, each for one job:
There is no self-serve delete today. Email riley@cortexanalytics.app and we will delete your organization’s data within 30 days of the request.
To be straight about where we are: Cortex is not SOC 2 certified today. Certification is on the roadmap, and we can walk your team through how the controls above are implemented on request. If a security review is part of your buying process, email us and we will work through it directly.
See also our privacy policy and terms of service.
Start a free account — no credit card
Questions? riley@cortexanalytics.app