AdPropixAdPropix

    Security Policy

    Last updated: January 30, 2026

    1. Our Commitment to Security

    At AdPropix, security is fundamental to everything we do. We are committed to protecting your data with industry-leading security measures and maintaining the trust you place in us. This Security Policy outlines our approach to keeping your information safe.

    2. Data Encryption

    2.1 In Transit

    All data transmitted between your browser and our servers is protected using TLS 1.3 encryption with 256-bit AES. We enforce HTTPS across our entire platform and use HSTS to prevent downgrade attacks.

    2.2 At Rest

    Data stored in our databases is encrypted using AES-256 encryption. Encryption keys are managed using secure key management services with regular key rotation.

    3. Infrastructure Security

    • Cloud Hosting: We use enterprise-grade cloud infrastructure with SOC 2 Type II certification
    • Network Security: Multiple layers of firewalls, DDoS protection, and intrusion detection systems
    • Access Controls: Strict role-based access controls and principle of least privilege
    • Monitoring: 24/7 security monitoring and automated threat detection
    • Backup: Regular encrypted backups with geographic redundancy

    4. Application Security

    • Secure software development lifecycle (SDLC)
    • Regular code reviews and security audits
    • Automated vulnerability scanning
    • Penetration testing by third-party security firms
    • Input validation and output encoding to prevent injection attacks
    • Protection against OWASP Top 10 vulnerabilities

    5. Authentication & Access

    • Secure password requirements and hashing using bcrypt
    • Multi-factor authentication (MFA) available for all accounts
    • Session management with automatic timeout
    • Brute force protection and account lockout policies
    • OAuth 2.0 integration for third-party services

    6. Compliance & Certifications

    AdPropix maintains compliance with:

    • SOC 2 Type II: Independent verification of security controls
    • GDPR: European data protection requirements
    • CCPA: California consumer privacy regulations
    • Meta Business Partner: Compliance with Meta's security requirements
    • PCI DSS: Payment card industry standards (via our payment processor)

    7. Employee Security

    • Background checks for all employees with data access
    • Mandatory security awareness training
    • Strict access controls based on job function
    • Confidentiality agreements and security policies
    • Regular security training and phishing simulations

    8. Incident Response

    We maintain a comprehensive incident response plan that includes:

    • 24/7 security incident monitoring
    • Defined escalation procedures
    • Containment and eradication processes
    • Post-incident analysis and improvement
    • Customer notification within 72 hours of confirmed data breaches

    9. Vulnerability Disclosure

    We welcome responsible disclosure of security vulnerabilities. If you discover a security issue, please report it to:

    Email: security@adpropix.io

    We commit to acknowledging reports within 24 hours and working with researchers to address issues promptly.

    10. Your Security Responsibilities

    To help keep your account secure:

    • Use a strong, unique password for your AdPropix account
    • Enable multi-factor authentication
    • Keep your devices and browsers updated
    • Be vigilant against phishing attempts
    • Report suspicious activity immediately
    • Review connected applications regularly

    11. Contact

    For security-related inquiries:

    AdPropix Pty Ltd — Security Team

    ABN: 56 696 674 656 | ACN: 696 674 656

    Level 10, 14 Mason Street, Dandenong VIC 3175, Australia

    Email: security@adpropix.io

    General Support: support@adpropix.io

    Phone: +61 402 018 828