Security. Your accounts, and the keys to them.
Connecting an ad account means handing over spending authority. These are the controls that sit behind that decision.
Last updated: March 2026
The controls, stated plainly.
Data encryption
Encrypted in transit with TLS and at rest with AES-256. API tokens and OAuth credentials are stored encrypted, under keys separate from the application data.
We never hold your passwords
Ad platforms are connected over OAuth, so your Google, Meta and Microsoft credentials are never sent to us and never stored. Revoke our access from the platform at any time.
Access controls
Role-based permissions inside your workspace, and multi-factor authentication required on every account with production access on our side.
Least privilege
Production access is restricted to the people whose job requires it, granted per task rather than standing, and reviewed as the team changes.
Your data is not the product
We do not sell your data, share it with other customers, use it to target advertising, or train models on it. It is used to run your account and nothing else.
Incident response
A documented plan with named escalation ownership. Affected customers are notified within 72 hours, and every incident gets a written post-incident review.
Responsible disclosure.
If you find a vulnerability, report it and we will work with you. We acknowledge reports within 2 business days and will not pursue legal action against researchers who follow these guidelines.
- Email your findings to security@advertisingsystems.ai.
- Provide enough detail for us to reproduce and address the issue.
- Allow reasonable time to investigate and remediate before public disclosure.
- Do not access, modify or delete other users' data.
Common questions
Is my data encrypted?
Yes. Data is encrypted in transit with TLS and at rest with AES-256. API tokens and OAuth credentials are stored encrypted, under keys separate from the application data.
Are you SOC 2 certified?
Not today. We are not going to claim a certification we do not hold — if you ask this question, you will check. We are happy to complete your security questionnaire and walk through our controls in detail, and we will say plainly where a control is a practice rather than an audited artefact.
How do I report a security issue?
Email security@advertisingsystems.ai with details. We respond within 2 business days and don’t pursue legal action against researchers who follow responsible disclosure.
Do you sell or share my data?
No. We don’t sell your data, share it with other customers, use it to target advertising, or train models on it. It is used to run your account and nothing else. See our Privacy Policy.
Where is data stored?
On managed cloud infrastructure. If you have a specific residency requirement, ask before you sign — we will tell you whether we can meet it rather than assume.
How do you handle access to production?
Production access requires multi-factor authentication, is limited to the people whose job needs it, and is granted per task rather than standing.
What about GDPR or CCPA?
We support data subject access, export and deletion requests. See our Privacy Policy for the full detail and how to make a request.
Can I get a security questionnaire or SIG?
Yes. Send it over and we will complete it, including the questions where the honest answer is “not yet”. Contact security@advertisingsystems.ai.
How are credentials stored?
Ad platforms connect over OAuth, so we never receive or store your Google, Meta or Microsoft passwords. The OAuth tokens we do hold are encrypted, and you can revoke our access from the platform at any time.
Questions about security or compliance? Contact us →