Security you can build on
Encryption, access management, secure development, vulnerability management, and incident response — the controls that protect your data and platform integrity.
Encryption
TLS 1.2+ in transit and AES-256 at rest across all storage systems.
Access control
Role-based access, MFA, and least-privilege with periodic access reviews.
Monitoring & audit
Audit logging, anomalous-access detection, and platform health monitoring.
Vulnerability management
Continuous scanning, prioritized remediation, and responsible disclosure.
Secure development
Mandatory code review, dependency scanning, and environment isolation.
Incident response
Documented plan with breach notification within 72 hours of confirmation.
1. Security Overview
ADGTech's security program is designed using enterprise security principles aligned with industry frameworks including the SOC 2 Trust Service Criteria. Our program covers infrastructure security, application security, data protection, access management, and incident response.
ADGTech does not claim SOC 2 certification at this time. SOC 2 Type II certification is in progress. Enterprise customers can request our current security and compliance documentation package.
2. Encryption
Encryption in Transit
All data transmitted between clients and ADGTech platform endpoints is protected using TLS 1.2 or higher. We enforce HTTPS across all platform surfaces and reject insecure connections.
Encryption at Rest
Customer data stored on ADGTech infrastructure is encrypted at rest using AES-256 or equivalent industry-standard encryption. Database-level and disk-level encryption controls are applied.
3. Access Controls
Role-Based Access Control (RBAC)
The Platform enforces role-based access control. Customers can define roles and permissions for their authorized users, limiting access to data and features based on job function.
Multi-Factor Authentication
Multi-factor authentication (MFA) is supported for platform accounts. Enterprise customers are encouraged to enforce MFA for all authorized users through their account settings.
Least Privilege Principle
ADGTech's internal team follows least-privilege access principles. Access to customer data is limited to personnel with a documented business need, subject to access reviews.
Access Reviews
Internal access permissions are reviewed periodically to ensure access is appropriate and revoked when no longer needed.
4. Audit Logging
Platform actions, authentication events, API calls, and administrative changes are logged. Enterprise customers can request audit log exports. Logs are retained for a minimum of 90 days and up to 12 months depending on subscription tier.
5. API Security
API access is authenticated using secure token-based authentication. API keys are scoped by permission level. Rate limiting and anomaly detection controls are applied to API endpoints. Customers should rotate API keys regularly and store them securely.
6. Secure Development Practices
ADGTech follows secure software development practices including: code review requirements before deployment; dependency scanning for known vulnerabilities; separation of production and development environments; secrets management using environment isolation; and regular review of third-party dependencies.
7. Backup and Recovery
Customer data is backed up on a regular schedule. Backup integrity is tested periodically. Recovery procedures are documented and tested as part of our business continuity program.
8. Vulnerability Management
ADGTech maintains a vulnerability management program that includes: regular scanning of platform components for known vulnerabilities; tracking and prioritization of identified vulnerabilities; timely patching and remediation; and a responsible disclosure process for external security reports.
To report a vulnerability: security@adgtech.ai
9. Incident Response
ADGTech maintains a documented incident response plan. In the event of a security incident affecting customer data:
- Incidents are triaged and contained as quickly as possible
- Affected customers are notified within 72 hours of confirmed breach detection
- Post-incident reviews identify root cause and prevention measures
- Regulatory notifications are made where required by applicable privacy law
10. Monitoring
ADGTech operates platform monitoring covering: availability and performance; security event detection; anomalous access pattern detection; and infrastructure health. Alerts are routed to on-call team members for timely response.
11. Customer Security Responsibilities
Customers are responsible for: maintaining secure credentials and enforcing MFA; configuring appropriate user permissions within their account; keeping integration credentials and API keys secure; and promptly reporting suspected security incidents to security@adgtech.ai.
Reporting a vulnerability or running a security review?
Reach our security team directly at security@adgtech.ai — reports are acknowledged within one business day.
Frequently Asked Questions
Is ADGTech SOC 2 certified?
ADGTech is designed using SOC 2 Trust Service Criteria as a security framework. Formal SOC 2 Type II certification is in progress. Enterprise customers can request our current security documentation.
Does ADGTech support MFA?
Yes. Multi-factor authentication (MFA) is supported for platform accounts.
How do I report a security vulnerability?
Contact security@adgtech.ai. Security reports are acknowledged within 1 business day and investigated promptly.