Trust & security
Bank-grade controls for your advertising budgets.
ADmetric AI handles customer funds and connects to platforms that bill in real time. Security is not a feature — it is the product.
Encryption everywhere
AES-256 at rest, TLS 1.3 in transit, hardware-backed key storage for OAuth tokens and API credentials.
SOC 2 Type II in progress
Independent audit ongoing with a Big-Four firm. Quarterly internal reviews of access, change management, and incident response.
Scoped platform access
We request the narrowest OAuth scopes each ad network exposes — budget and billing only. We do not create, edit, or pause ad creatives.
EU-resident infrastructure
Primary region eu-central. Encrypted backups across two regions with point-in-time recovery.
Segregated client funds
Top-ups are held in a segregated account at a regulated EMI partner. Funds are never commingled with operating capital.
Full ledger transparency
Every movement — top-up, allocation, refill, refund — is recorded as an immutable, exportable ledger entry mapped to a platform receipt.
Compliance roadmap
- SOC 2 Type I — completed Q1 2026.
- SOC 2 Type II — observation window in progress, report expected Q4 2026.
- ISO 27001 — gap assessment complete, certification targeted H1 2027.
- PCI DSS — SAQ-A. Card data is tokenised by our payment partner and never touches our servers.
- GDPR / UK GDPR — Data Processing Addendum and Standard Contractual Clauses available on request.
How we handle ad-platform credentials
Every connection is established via the platform's official OAuth flow. Refresh tokens are stored in an isolated key-management service and only released to a short-lived signing worker at the moment a budget call is made. No engineer has standing access to a customer's connected accounts.
Incident response
A documented runbook governs containment, notification, and remediation. We commit to notifying affected customers within 72 hours of confirming a personal-data incident, and within 24 hours for any incident affecting funds movement.
Responsible disclosure
If you believe you have found a vulnerability, email security@admetric.ai with reproduction steps. We respond within one business day and operate a non-monetary bounty programme.
Status & subprocessors
Real-time uptime and a current list of subprocessors are published and updated continuously.