> ## Documentation Index
> Fetch the complete documentation index at: https://docs.superscale.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & compliance

> How to think about privacy, data boundaries, commercial rights, legal review, and regulated ad workflows.

Security and compliance questions usually come up when teams want to use real client assets, regulated claims, customer testimonials, or connected ad accounts. The right setup is simple: put the rules in context, keep humans in approval, and separate private data, platform permissions, and generated creative rights.

## What to put in context

<CardGroup cols={2}>
  <Card title="Claim rules">
    What you can say, what you cannot say, required disclaimers, and platform-specific restrictions.
  </Card>

  <Card title="Brand safety rules">
    Forbidden visuals, sensitive claims, testimonial rules, competitor restrictions, and tone boundaries.
  </Card>

  <Card title="Approval workflow">
    Who reviews legal, brand, product, and media-buying decisions before launch.
  </Card>

  <Card title="Data boundaries">
    Which assets are public, confidential, client-owned, unreleased, or restricted.
  </Card>
</CardGroup>

## Human approval matters

Superscale can help produce, review, and iterate creative quickly, but high-stakes decisions should stay human-in-the-loop:

* Legal claims and substantiation.
* Health, finance, employment, or other regulated categories.
* Testimonials, endorsements, or AI-generated people.
* Budget changes and campaign launch decisions.
* Client-confidential or unreleased product assets.

<Note>
  Treat compliance context like brand context: make it durable. If a rule should apply to every generation, put it at brand or workspace level instead of repeating it in chat.
</Note>

## Privacy and model processing

When you upload assets or ask for generations, Superscale may need to process selected inputs through the systems that power research, generation, analysis, storage, and delivery. For sensitive material, check your agreement, DPA, subprocessors, and account settings before uploading.

If your team has strict rules around model-provider processing, confidential client material, unreleased hardware, or customer data, set those rules with your Superscale contact before putting that material into context.

## Commercial use and generated assets

Generated creatives are designed for advertising use. Before launching, review:

* Whether the creative uses approved brand assets.
* Whether any testimonial or person-like creative is allowed for your category.
* Whether the output makes claims you can substantiate.
* Whether the platform you publish to has special AI, political, health, financial, or restricted-category rules.

## Regulated-brand workflow

<Steps>
  <Step title="Upload the rules" icon="file-lock">
    Add legal guidelines, claim restrictions, platform rules, forbidden examples, and required disclaimers as context.
  </Step>

  <Step title="Generate within guardrails" icon="wand-sparkles">
    Tell the agent to follow those rules and avoid unsupported claims.
  </Step>

  <Step title="Review before launch" icon="shield-check">
    Have a human approve claims, visuals, disclaimers, testimonials, and final media-buying actions.
  </Step>

  <Step title="Save corrections" icon="refresh-cw">
    If an output violates a rule, turn the correction into durable context so it is less likely to happen again.
  </Step>
</Steps>

## Common questions

<AccordionGroup>
  <Accordion title="Can I upload confidential client assets?" icon="lock">
    You can use Superscale for client work, but confidential material should follow your contract, DPA, and internal policy. If the asset is sensitive or unreleased, confirm the processing boundary first.
  </Accordion>

  <Accordion title="Can Superscale create testimonials with AI people?" icon="user-check">
    Only use testimonial-style creative where it is allowed, truthful, and reviewed. Regulated or trust-sensitive categories should be especially careful with AI people, implied endorsements, and claims.
  </Accordion>

  <Accordion title="Where should compliance rules live?" icon="folder-tree">
    Put rules at the lowest level where they are always true: workspace for agency-wide rules, brand for one client's legal boundaries, product for a specific offer.
  </Accordion>

  <Accordion title="Does connecting an ad account let Superscale spend automatically?" icon="shield-alert">
    Publishing and budget actions should be approval-gated. Use read-only access if you only want analysis.
  </Accordion>
</AccordionGroup>
