Trust center
Security you can verify, not promises you can't.
Everything below is implemented in the product today. We describe what we actually do — and plainly state what we don't claim.
Encrypted in transit
Every connection to Adsevon is served over HTTPS (TLS). Production enforces HSTS and a strict Content-Security-Policy, so traffic between your browser and our servers cannot be read or modified in flight.
Passwords, properly handled
Passwords are hashed with bcrypt (cost factor 12) and never stored or logged in plaintext. New passwords are checked against known breach data at signup.
Your workspace is yours alone
Every data query in the product is scoped to your workspace — tenant isolation is enforced in code and verified by automated tests that prove no workspace can read or modify another’s data.
Read-only by design
Ad platform connectors request read-only scopes. Adsevon analyzes your advertising data and recommends actions — it never changes your campaigns, budgets, or bids on its own.
Sessions you control
Sessions live server-side with a 30-day absolute lifetime, HttpOnly + Secure + SameSite cookies, and are revoked automatically on password reset. Optional TOTP two-factor authentication is available once configured.
Single-use, expiring tokens
Email verification and password-reset tokens are 256-bit random values, stored hashed, expiring after 24 hours and 30 minutes respectively, and consumed atomically so they can never be reused.
Rate limiting everywhere it matters
Login, signup, password reset, imports, and API actions are rate limited; production uses a shared Redis-backed limiter so limits hold across all servers.
Audit trail
Authentication events, imports, recommendation changes, and settings changes are written to an append-only audit trail.
Your data, exportable and deletable
Your campaign data is yours. Export it any time from Data, and delete your workspace — including everything in it — from Settings. Uploaded file bytes are cleared after a successful import.
What we don't claim
Adsevon has not undergone SOC 2, ISO 27001, or similar third-party security audits, and we do not claim formal GDPR/CCPA certification. We follow privacy-by-design practices, and our policies will be reviewed by counsel before public launch. We'd rather tell you exactly where we stand than borrow credibility we haven't earned.
Found a vulnerability?
Email security@adsevon.com. We'll acknowledge receipt promptly and work to resolve verified issues quickly.