Security
The controls in place today, in the words your questionnaire needs.
1. What this page is
A description of the controls around the Adferry Platform and this website. For contractual commitments see the DPA.
2. Data in transit and at rest
- All endpoints (ad serving, console, API, website) are served over TLS. Plain HTTP is redirected.
- Production data stores are reachable only from the application network, not from the public internet.
- IP addresses are used for geolocation and fraud scoring and can be truncated or hashed per customer configuration.
3. Access control
- Console and API access is role-based and scoped to the customer's account; a user sees only the inventory, campaigns and reports they are granted.
- Adferry staff access to production is limited to named engineers, individually authenticated, and reviewed periodically.
- Credentials are never shared in plain text and API keys can be rotated by the customer.
4. Tenant separation
Each customer's data is keyed to its account in storage and in every query path. Reporting and request-level diagnostics are filtered by account before they reach the console or API.
5. Logging and auditability
- Every ad request keeps a record of what happened to it: the decision, its inputs, whether the creative rendered, whether the beacon landed, and how it was billed.
- Administrative actions in the console and API (user, method, path, result, time) are written to an audit log.
- Invoices are computed from the same measured-impression records the customer can inspect.
6. Availability and change safety
- If a configuration change starts hurting delivery, the Platform reverts to the last setup that was working.
- Pricing model changes run against the current model on a limited share of traffic and have to beat it before taking over; the customer can stop the test at any point.
- Planned maintenance is announced in advance. Uptime commitments, where given, are in the customer's order form.
7. Invalid traffic and platform abuse
Invalid traffic is scored and filtered before the auction, so it does not reach demand and does not appear on invoices. Creatives can be blocked per account, and inventory that misrepresents itself can be removed under the Terms.
8. Vulnerability reporting
Report security issues to our contact page (see also /.well-known/security.txt). We acknowledge within two business days and will not pursue good-faith research that respects user data and availability.
9. What we do not claim
We do not currently hold third-party security certifications or industry accreditations, and we do not state that we do. When that changes, it will appear here with the report available under NDA.