Security & Vulnerability Disclosure

Last updated: August 6, 2026

We take the security of our customers' advertising accounts and data seriously. If you believe you have found a vulnerability in AdControlCenter, we want to hear about it. This page explains what we consider in scope, how to report, and what to expect back.

No paid bounty

AdControlCenter does not operate a paid bug bounty program, and we do not offer monetary rewards for reports. We do offer prompt triage, a direct line to the engineer who will fix the issue, and — if you would like it — public credit once the fix has shipped. Please do not submit a report expecting payment or an invoice to be honoured.

How to report

Email security@adcontrolcenter.com. A useful report includes:

Reports that consist only of automated scanner output, with no demonstrated impact, will be closed without detailed response.

In scope

Issues we care most about: tenant isolation failures (reading or writing another workspace's data), authentication or session flaws, server-side request forgery, remote code execution, injection, exposure of OAuth tokens or API credentials, and payment or entitlement bypass.

Out of scope

Rules of engagement

What to expect

Safe harbor

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not pursue or support legal action against you in relation to it, and we will help make it known that your actions were conducted in compliance with this policy if a third party raises the matter. If in doubt about whether a specific test is acceptable, ask us before you run it.

Machine-readable policy

This policy is referenced from /.well-known/security.txt per RFC 9116.