Loading...
Loading...
Loading...
Security is foundational to everything we do. Learn how AdsMAA protects your data and keeps your information safe.
Last Updated: December 28, 2025
AdsMAA is built with security at its core. We handle sensitive advertising and conversion data, and we take this responsibility seriously. Our security program is designed to protect your data through industry-leading practices, continuous monitoring, and regular assessments.
Hosted on Amazon Web Services (AWS) with SOC 2 Type II certification. Multi-region deployment for high availability and disaster recovery.
VPC isolation, private subnets, Web Application Firewall (WAF), and DDoS protection through AWS Shield.
Complete data isolation between tenants. Each organization's data is logically separated and encrypted with unique keys.
Automated daily backups with point-in-time recovery. Data replicated across multiple availability zones.
PII Hashing: Personally identifiable information like email addresses and phone numbers are hashed using SHA-256 before being sent to advertising platforms for conversion matching.
| Role | Permissions |
|---|---|
| Owner | Full access, billing, team management, delete organization |
| Admin | Full access except billing and organization deletion |
| Manager | Manage campaigns, integrations, view reports |
| Analyst | View-only access to dashboards and reports |
All inputs validated and sanitized to prevent injection attacks
Token-based protection on all state-changing requests
Content Security Policy headers and output encoding
Parameterized queries and ORM-based database access
API rate limiting to prevent abuse and DDoS
HSTS, X-Frame-Options, X-Content-Type-Options enforced
Continuous monitoring of infrastructure, applications, and security events. Automated alerting for anomalies and potential threats.
Comprehensive audit logs for all security-relevant events. Immutable log storage with 90-day retention. Available for enterprise customers on request.
Documented incident response procedures. Security team on-call 24/7. Regular incident response drills and post-mortems.
Annual penetration testing by independent security firms. Quarterly vulnerability scans. Continuous automated security testing in CI/CD pipeline.
Automated dependency scanning for known vulnerabilities. Regular updates and patching. Software composition analysis (SCA) in development workflow.
Security training for developers. Code review requirements. SAST and DAST testing. Security review for significant changes.
We welcome responsible disclosure of security vulnerabilities. If you discover a potential security issue, please email [email protected]. We commit to acknowledging reports within 24 hours and providing updates as we investigate.
Full compliance with EU General Data Protection Regulation.
Hosted on SOC 2 Type II certified infrastructure (AWS).
Payment processing through PCI-compliant providers (Stripe, Razorpay).
DPA with SCCs available for enterprise customers.
Our disaster recovery plan includes multi-region failover, regular backup testing, and documented recovery procedures. Enterprise customers receive dedicated support and priority during incidents.
For security questions, vulnerability reports, or to request security documentation:
Security Team
[email protected]Enterprise Security
[email protected]Address: Zusta Autonetic Private Limited, 2/164A VC, Kolkata - 700047, India