SECURITY

Built like conversion infrastructure, not a tracking toy.

Sygna handles ad credentials and conversion events, so the product is designed around encryption, signed requests, merchant approval, and clear deletion paths.

Sygna security model

AES-256-GCM
HMAC
Approval workflow
Public deletion path

Encrypted secrets

Meta access tokens, GA4 API secrets, and future OAuth refresh tokens are encrypted at rest with AES-256-GCM and never returned in plain text after saving.

Signed site traffic

WooCommerce server events use per-site credentials and HMAC signatures so the API can reject forged event traffic.

Approval-first automation

High-impact strategy changes are proposed for merchant approval before activation. Sygna is not a hidden auto-editing tag manager.

Data minimization

Sygna avoids payment data and raw customer passwords. Customer identifiers are hashed when used for destination matching.

Revocation and deletion

Connections can be disconnected, plugin traffic can be stopped, and deletion instructions are public.

No GTM dependency

Sygna does not require editing a merchant's GTM container, reducing hidden tag conflicts and implementation drift.

Questions about security or data handling?

[email protected]