Security Policy
Last updated: January 30, 2026
1. Our Commitment to Security
At AdPropix, security is fundamental to everything we do. We are committed to protecting your data with industry-leading security measures and maintaining the trust you place in us. This Security Policy outlines our approach to keeping your information safe.
2. Data Encryption
2.1 In Transit
All data transmitted between your browser and our servers is protected using TLS 1.3 encryption with 256-bit AES. We enforce HTTPS across our entire platform and use HSTS to prevent downgrade attacks.
2.2 At Rest
Data stored in our databases is encrypted using AES-256 encryption. Encryption keys are managed using secure key management services with regular key rotation.
3. Infrastructure Security
- Cloud Hosting: We use enterprise-grade cloud infrastructure with SOC 2 Type II certification
- Network Security: Multiple layers of firewalls, DDoS protection, and intrusion detection systems
- Access Controls: Strict role-based access controls and principle of least privilege
- Monitoring: 24/7 security monitoring and automated threat detection
- Backup: Regular encrypted backups with geographic redundancy
4. Application Security
- Secure software development lifecycle (SDLC)
- Regular code reviews and security audits
- Automated vulnerability scanning
- Penetration testing by third-party security firms
- Input validation and output encoding to prevent injection attacks
- Protection against OWASP Top 10 vulnerabilities
5. Authentication & Access
- Secure password requirements and hashing using bcrypt
- Multi-factor authentication (MFA) available for all accounts
- Session management with automatic timeout
- Brute force protection and account lockout policies
- OAuth 2.0 integration for third-party services
6. Compliance & Certifications
AdPropix maintains compliance with:
- SOC 2 Type II: Independent verification of security controls
- GDPR: European data protection requirements
- CCPA: California consumer privacy regulations
- Meta Business Partner: Compliance with Meta's security requirements
- PCI DSS: Payment card industry standards (via our payment processor)
7. Employee Security
- Background checks for all employees with data access
- Mandatory security awareness training
- Strict access controls based on job function
- Confidentiality agreements and security policies
- Regular security training and phishing simulations
8. Incident Response
We maintain a comprehensive incident response plan that includes:
- 24/7 security incident monitoring
- Defined escalation procedures
- Containment and eradication processes
- Post-incident analysis and improvement
- Customer notification within 72 hours of confirmed data breaches
9. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:
Email: security@adpropix.io
We commit to acknowledging reports within 24 hours and working with researchers to address issues promptly.
10. Your Security Responsibilities
To help keep your account secure:
- Use a strong, unique password for your AdPropix account
- Enable multi-factor authentication
- Keep your devices and browsers updated
- Be vigilant against phishing attempts
- Report suspicious activity immediately
- Review connected applications regularly
11. Contact
For security-related inquiries:
AdPropix Pty Ltd — Security Team
ABN: 56 696 674 656 | ACN: 696 674 656
Level 10, 14 Mason Street, Dandenong VIC 3175, Australia
Email: security@adpropix.io
General Support: support@adpropix.io
Phone: +61 402 018 828