Trust & security

Bank-grade controls for your advertising budgets.

ADmetric AI handles customer funds and connects to platforms that bill in real time. Security is not a feature — it is the product.

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit, hardware-backed key storage for OAuth tokens and API credentials.

SOC 2 Type II in progress

Independent audit ongoing with a Big-Four firm. Quarterly internal reviews of access, change management, and incident response.

Scoped platform access

We request the narrowest OAuth scopes each ad network exposes — budget and billing only. We do not create, edit, or pause ad creatives.

EU-resident infrastructure

Primary region eu-central. Encrypted backups across two regions with point-in-time recovery.

Segregated client funds

Top-ups are held in a segregated account at a regulated EMI partner. Funds are never commingled with operating capital.

Full ledger transparency

Every movement — top-up, allocation, refill, refund — is recorded as an immutable, exportable ledger entry mapped to a platform receipt.

Compliance roadmap

  • SOC 2 Type I — completed Q1 2026.
  • SOC 2 Type II — observation window in progress, report expected Q4 2026.
  • ISO 27001 — gap assessment complete, certification targeted H1 2027.
  • PCI DSS — SAQ-A. Card data is tokenised by our payment partner and never touches our servers.
  • GDPR / UK GDPR — Data Processing Addendum and Standard Contractual Clauses available on request.

How we handle ad-platform credentials

Every connection is established via the platform's official OAuth flow. Refresh tokens are stored in an isolated key-management service and only released to a short-lived signing worker at the moment a budget call is made. No engineer has standing access to a customer's connected accounts.

Incident response

A documented runbook governs containment, notification, and remediation. We commit to notifying affected customers within 72 hours of confirming a personal-data incident, and within 24 hours for any incident affecting funds movement.

Responsible disclosure

If you believe you have found a vulnerability, email security@admetric.ai with reproduction steps. We respond within one business day and operate a non-monetary bounty programme.

Status & subprocessors

Real-time uptime and a current list of subprocessors are published and updated continuously.

View status page