Security is foundational.
How AdTubio protects customer data, controls access, and responds to incidents.
Program overview
AdTubio's security program is built around a few clear principles: least-privilege access, defense in depth, encrypted transport and storage, and responsible handling of the data our customers entrust to us. This page describes the controls we operate today and is maintained by AdTubio.
For a plain-language summary aimed at buyers, see our Trust page.
Infrastructure
The AdTubio platform runs on trusted cloud infrastructure operated by established providers. Production systems are isolated from development and staging environments, and administrative access is restricted to a small group of engineers.
Encryption
Traffic between your browser and AdTubio is encrypted using TLS. Customer data is encrypted at rest using industry-standard algorithms provided by our infrastructure partners.
Authentication and access control
User accounts are protected by passwords hashed with modern algorithms and by session tokens with server-side expiration. Role-based access controls apply throughout the platform so that users only see the workspaces and data they are permitted to access.
Internal access to production systems requires strong authentication and is granted on a least-privilege basis.
Application security
Code changes are reviewed before merge. Dependencies are monitored for known vulnerabilities, and we apply security updates on a regular cadence.
We take input validation, output encoding, and safe handling of user-controlled data seriously across the codebase.
Data handling and retention
We collect only the data needed to operate the service. Retention is scoped to the lifetime of your workspace, with additional periods only where required for legal, tax, or security reasons.
See the Privacy Policy for more detail on what we collect and how it is used.
Subprocessors
AdTubio uses a small number of subprocessors for hosting, payments, email, and analytics. Each is reviewed for security posture and data-handling practices before we integrate, and reviewed again on a periodic basis.
Backups and availability
Customer data is backed up on a regular schedule and restore procedures are tested. We monitor platform availability and investigate anomalies as part of routine operations.
Incident response
We maintain an internal incident-response process covering detection, containment, notification, and post-incident review. Where an incident affects customer data, we will notify affected customers in line with applicable law.
Responsible disclosure
If you believe you have found a security issue in AdTubio, please report it privately to security@adtubio.com. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure. We will acknowledge your report and keep you informed of progress.
Related
Looking for the buyer-friendly summary?
The Trust page gathers the highlights of our security and privacy posture in one place for procurement reviews.
