AdFence legal

Responsible disclosure policy

Last updated 08/08/2026

AdFence watches ad accounts for signs of compromise, so we hold our own security to the standard we sell. If you believe you have found a vulnerability in AdFence, we want to hear about it, and we will work with you to verify and fix it.

This page tells you how to report, what is in scope, what to expect from us, and the safe harbor we extend to good-faith research.

How to report

Email [email protected]. Include what you can:

  • A description of the issue and where it lives: a URL, an endpoint, or a feature.
  • Steps to reproduce it, a proof of concept, or both.
  • Your assessment of what an attacker could gain from it.
  • Your name or handle, if you would like public credit once it is fixed.

In scope

  • The AdFence web application and its server endpoints, on the domain serving this page.
  • Authentication, session handling, and workspace isolation: any way one customer could read or change another customer's data.
  • The OAuth flows that connect Meta, Google and TikTok ad accounts, and the tokens they handle.
  • Billing, plan enforcement, and the Kill Switch and step-up verification flows.

Out of scope

  • The ad platforms themselves (Meta, Google, TikTok, Shopify). Report platform vulnerabilities to the platform.
  • Third-party services we build on (Stripe, SendGrid, Crisp, and the other processors named in our data processing disclosure). Report those to the vendor.
  • Volumetric denial of service and resource-exhaustion flooding. A BYPASS of a rate limit is in scope; drowning one is not.
  • Social engineering of our staff or our customers, phishing, and physical attacks.
  • Output from automated scanners with no demonstrated impact, and missing-best-practice notes with no exploitable path.

Rules of engagement

  • Test only against accounts and workspaces you own. Never read, change, or delete another customer's data.
  • If you encounter data that is not yours, stop, do not save or share it, and tell us what you saw in your report.
  • Do not exfiltrate data. The minimum evidence that demonstrates the issue is enough.
  • Do not run denial-of-service or destructive tests against the service.
  • Give us time to fix the issue before disclosing it publicly. We ask for 90 days from your report, and we will tell you if we need to discuss more.

What to expect from us

  • We will acknowledge your report within 5 business days.
  • We will tell you whether we can reproduce the issue, and keep you informed while we work on a fix.
  • When the issue is fixed we will tell you, and we are glad to credit you publicly if you want that.

Safe harbor

If you make a good-faith effort to follow this policy, we consider your research authorized. We will not pursue legal action against you for it, and we will not refer it to law enforcement.

If a third party takes legal action against you over research that followed this policy, we will make it known that your work was authorized.

This safe harbor does not cover research that breaks the rules above, targets systems we do not operate, or independently breaks the law.

AdFence does not run a paid bug bounty today; one may follow. What we promise now is a fast human response and public credit if you want it.

Machine-readable version: security.txt.