Security and data, in the questions

Security and data protection, answered in full.

What procurement, legal and a data protection officer ask before anyone signs, including the certifications that are not held, the retention rules that are enforced in code, and the straight answer about what happens to a prepaid wallet balance if this company fails.
questions in this group, each answered in full
9
pages the answers are written on, every one linked
1
questions across the whole set
148
Elsewhere in the questions
9 questions

Security

Written on Security, and rendered here in the same words rather than summarised.

Read the page these answers live on →

Are you ISO 27001 certified?

No. Nor SOC 2, nor Cyber Essentials, and no third-party penetration test has been commissioned. ICO registration and the exposure-ledger impact assessment are also open items rather than completed ones. If a certification is a hard procurement requirement, we do not clear it today, and there is no benefit to either side in exploring further. What exists instead is a documented, fail-closed architecture and a published account of what is not held — on this page, rather than discovered in a questionnaire.

How long do you keep personal data?

Hashed mobile advertising ids are held for at most 90 days, after which they are persistently stripped from the exposure event, re-grading it to a coarser key rather than deleting the record. Campaign configuration, plans and delivery data are held for the life of your workspace and deleted on request. Vendor credentials are encrypted at rest with AES-256-GCM and are deleted when the connection is removed.

Who can see my campaign data?

Your advertiser workspace is the scope boundary for every route, and a cross-tenant request returns a 404 rather than a 403, because a 403 confirms that the resource exists. Actor, source and client attribution are persisted on every action and readable in the audit log. The disclosure that belongs beside that: the audit log records what came through the API, not what someone with direct database access could read, and during a design-partner engagement that someone is us. No certification attests to how that access is controlled, because we hold none.

Can an AI agent authorise spend on my account?

No. Agents cannot hold the exact-digest approval permission, cannot resolve human approvals, cannot revoke or replace authority and cannot close missions. Consequential calls fail closed unless the request matches an approval a human granted for those exact bytes, and enabling spend on a staged live line is a separately granted action that approval alone cannot perform.

What is your lawful basis for the targeting data?

It varies by segment, which is exactly why it is recorded per segment rather than asserted once. Every compiled plan carries a manifest naming each segment's provider and its basis: consent-chained where the provider asserts a consent chain, legitimate interest where the segment relies on one, and outside scope for cinema and DOOH, which involve no personal data in delivery at all. Where a segment match is weak or a geography is unmapped, the warning stays attached to the plan.

Is my data used to train AI models?

No. Briefs and campaign data are sent to the model provider to produce your output and are not used for training. The whole AI layer also has a complete deterministic fallback, so the product runs with no model provider configured at all.

Where does the data live, and can we keep it in the UK?

Yes, because there is no multi-tenant hosted service to be in the wrong place. A deployment today is one that is stood up for you — a single virtual machine running the API, dashboard and MCP server behind a reverse proxy, or the three split across a container host — so residency is a deployment decision rather than a fixed answer. Reporting runs on a Europe/London calendar and the money surface is sterling only.

Who are your subprocessors?

Four today: Anthropic for the AI layer, Clerk for authentication, Stripe for wallet top-ups and Plausible for cookieless analytics. That is deliberately shorter than the list in our own legal templates, which is wrong in both directions — it names six vendors as active recipients that are fail-closed stubs receiving nothing, and omits the AI media providers that receive prompts once asset production is enabled. A short accurate list is more use to you than a long inaccurate one.

What happens to my money if you fail as a company?

The prepaid wallet is a real exposure and it deserves a straight answer: funds held in a wallet are a claim on Tenhaw LTD, not client money held in a segregated account. Wallet reservations against live campaigns are held until spend is reconciled to the provider's own invoice, which is designed to limit how far ahead of delivery the balance runs. Be exact about the status of that control: reconciling report rows to a provider invoice is one of the unmet conditions in the launch standard, so it has never once operated. And it would not make the balance bankruptcy-remote if it had. Fund what you are about to spend rather than a quarter in advance, and raise it in the design-partner contract if it matters to your finance team.

The security page

If the answer above raises a question about your own budget, that is the sort of thing a forty-five minute working session is for.

Talk it through
the rest of the questions

148 questions, grouped by subject

Every question answered anywhere on this site sits in one of 21 groups, and appears in exactly one of them. This is one.

All 148 questions, and every group →

book a working session

Bring the question this group did not answer.

45 minutes. Bring a real brief and we compile it live. You describe one audience, it compiles into seven channel plans in front of you, and the awkward questions get answered against your own numbers rather than in general.

Design-partner phase· recruiting paid design partners rather than selling self-serve media · what is live, and what is not

// pick a slot · cal.com/adbuymcp/working-sessionLIVE CALENDAR

Calendar not loading? Open it on cal.com or email hello@adbuymcp.com.