Security
Last updated 28 June 2026
Adgent connects to your advertising and analytics accounts, so protecting that access is core to the product, not an afterthought. This page explains the measures Adgent takes to keep your data and your connected accounts safe. For how we collect and use data, see our Privacy Policy; for what data we access and why, see Data Use.
01Our approach
We design Adgent around a few simple principles: collect only the access we need, protect it in transit and at rest, keep humans out of your data by default, and make every change to your accounts something you approve. Security is a continuous practice — the measures below describe our current safeguards, which we review and improve over time.
02Encryption
- In transit — all traffic to and from Adgent, and all calls to platform APIs, are encrypted using TLS (HTTPS).
- At rest — data we store, including connection tokens and cached reporting data, is encrypted at rest.
03Access tokens & secrets
When you connect a platform, we store the authorization tokens that let Adgent act on your behalf. We never ask for or store your platform passwords.
- Tokens are encrypted at rest and treated as secrets. They are used only to authenticate requests to the platform you connected, are never exposed to other customers, and are never included in AI prompts or sent to AI model providers.
- We request the minimum scopes needed for the features you use.
- You can revoke Adgent's access at any time from your Adgent settings or from the platform's own permission settings, which immediately stops new scheduled access.
- Application secrets and API credentials are kept confidential and rotated when appropriate.
04Access controls
Access to systems and data is governed by least-privilege principles. Internal access is limited to personnel who need it to operate the service, is authenticated, and is logged. We do not allow humans to read your connected data except in narrow circumstances: with your affirmative consent (for example, support you request), where necessary for security or to investigate abuse, where required by law, or where the data has been aggregated or de-identified for internal operations.
05Read-only by default
Adgent operates in read-only mode unless you grant execution access. Even with execution access, no change is applied to your accounts until you explicitly approve it. This approval gate is a security control as much as a product choice — it keeps automated changes from ever reaching your spend without your say-so.
06Infrastructure
Adgent runs on reputable cloud infrastructure providers that maintain industry-standard physical and network security and recognized certifications. Environments are isolated, and customer data is logically separated so that one customer cannot access another's data.
07Monitoring & logging
We log access to systems and key actions to support security, debugging, and abuse detection, and we monitor for anomalous activity. Logs are protected and retained for a limited period consistent with security and legal needs.
08Incident response
If we become aware of a security incident that compromises user data, we begin remediation immediately, investigate the cause, and notify affected users and the relevant platforms and authorities as required by applicable law and platform policies. We also report incidents to platforms where their terms require it.
09Service providers
We use a small set of trusted service providers (sub-processors) to host, operate, secure, and support Adgent, including cloud infrastructure and the AI model provider that processes data to generate your results. We require them to protect data, to use it only to provide their service to us, and to delete it when it is no longer needed. We do not sell your data, and we do not transfer it for advertising.
10Retention & deletion
We keep data only as long as needed to provide the service and for legitimate legal and security purposes. Disconnecting a platform stops new scheduled access but does not, by itself, delete data already stored by Adgent. A verified platform-data deletion request begins without undue delay. Deleting a company closes access immediately and schedules permanent deletion of its data from active systems within 30 days, subject to limited retention required by law. See Your rights & data deletion.
11Report a vulnerability
Found a security issue? We want to hear from you. Email [email protected] with the details and we will acknowledge your report and work to address it promptly. Please give us a reasonable chance to fix an issue before disclosing it publicly.
12Compliance
We build Adgent to align with applicable data-protection laws, including the GDPR and CCPA, and with the developer and data-protection requirements of the platforms we integrate with, including Meta and Google. As we grow, we continue to mature our security program and pursue recognized certifications and assessments.
Contact us
Security questions or reports? Email [email protected].
Adgent is operated by Osman Tıkna, a sole proprietorship established in Türkiye.