A2 GTM

Data Security

Last Updated: May 2, 2026
Owner: ACE Financials Technology, operating A2 GTM
Contact: [email protected]

A2 GTM is a B2B platform that handles sensitive customer data — including OAuth tokens for ad platforms, prospect lists, and campaign content. This page summarizes the controls we use to protect that data and how to report security issues. For full data-handling details, see our Privacy Policy.

Encryption

Access Control

Monitoring and Logging

Incident Response

Vendor and Subprocessor Security

Software Development Lifecycle

Backups and Disaster Recovery

Certifications and Compliance Status

Standard / FrameworkStatus
SOC 2 Type IIIn progress
ISO 27001Not started
HIPAANot in scope (A2 GTM is not a healthcare product; do not upload PHI)
PCI DSSNot directly in scope. Card data is handled by Stripe (PCI DSS Level 1).
GDPR / UK GDPRCompliant program — see Privacy Policy §9 and §13 for transfers.
CCPA / CPRACompliant program — see Privacy Policy §9.

We do not claim certifications we do not hold. Updates will be posted here as they are achieved.

Vulnerability Disclosure

If you believe you have discovered a security vulnerability in A2 GTM, please report it to us responsibly:

We acknowledge reports within 3 business days and provide a status update within 10 business days.

Customer Responsibilities

Security is shared. To keep your data safe:

Contact

Security issues and vulnerability reports: [email protected]
Privacy and data-subject requests: [email protected]
Legal notices: [email protected]

ACE Financials Technology
2647 Narnia Way, Suite 101
Land O Lakes, FL 34638, United States