Security
Built to be granted access to.
Adplainly holds read access to advertising data that belongs to you and your clients. This page describes what we do to deserve that, in plain terms.
- Read-only Meta permissions
- Adplainly requests ads_read and business_management through Facebook Login for Business. Neither permission allows changing campaigns, budgets, audiences or creatives, and the product has no code path that writes to Meta.
- Encryption
- All traffic uses TLS. Stored data — raw metrics, aggregates, account records — is encrypted at rest with AWS KMS-managed keys. Meta access tokens are held in AWS Secrets Manager, encrypted with a dedicated key, and are never written to logs.
- EU data centre
- Storage and processing run in AWS eu-central-1 (Frankfurt). The CDN edge that serves this site and the dashboard, and its access logs, run in AWS us-east-1.
- Least-privilege access
- Each component runs under its own IAM role with permissions limited to what it does. Human access uses AWS SSO with MFA, and production changes are made through reviewed infrastructure code, not by hand.
- Audit logging
- AWS CloudTrail records administrative actions. Application logs are structured, contain no tokens and no personal data beyond what is needed to trace a request, and are kept for a limited period.
- Deletion
- You can delete your data from the dashboard, by e-mail, or by removing Adplainly from your Meta account settings; every path leads to the same deletion routine that removes tokens, metrics and account records. See the data deletion page.
Reporting a vulnerability
Found something? Tell us first.
E-mail support@adplainly.com with "Security" in the subject. We acknowledge reports within two working days, keep you informed while we fix the issue, and will credit you if you wish. Please do not access data that is not yours, and give us reasonable time to fix before disclosing publicly.
Related: privacy policy · data deletion ·terms of service