Security & Compliance
Your data security is our top priority. Learn about the measures we take to protect your information and maintain compliance with global standards.
Certifications & Compliance
SOC 2 Type II
Annual audits verify our security controls meet the highest standards for data protection and availability.
GDPR Compliant
Full compliance with the EU General Data Protection Regulation. Data subject rights fully supported.
CCPA Compliant
California Consumer Privacy Act compliance with full transparency and consumer rights support.
ISO 27001
Information security management system certified to international standards.
Enterprise-Grade Security
We implement multiple layers of security to ensure your data is protected at every level.
- Encryption EverywhereTLS 1.3 in transit, AES-256 at rest
- Access ControlsRole-based access with multi-factor authentication
- Regular Penetration TestingThird-party security assessments quarterly
- 24/7 MonitoringReal-time threat detection and response
- DDoS ProtectionEnterprise-level protection via Cloudflare
Advertising Platform API Usage
MyClickShield integrates with the Google, Meta and Microsoft advertising APIs solely to provide click fraud protection to the authenticated advertiser. We never sell or share API data with third parties.
Google Ads API
OAuth scope: https://www.googleapis.com/auth/adwords
Purpose: Detect invalid clicks and help advertisers reduce wasted ad spend.
Services called:
CustomerService.listAccessibleCustomers— list authorized Google Ads accounts during OAuth setup.GoogleAdsService.searchStream— readENABLEDcampaigns so we know where to apply IP exclusions.CampaignCriterionService.mutate— add / remove negativeIP_BLOCKcriteria on campaigns. Every mutation is reversible from the dashboard.ConversionAdjustmentUploadService.uploadConversionAdjustments— uploadRETRACTIONadjustments for flagged clicks (opt-in).
User control: Every automated action is configurable, reversible, and auditable from the MyClickShield dashboard. The user may revoke OAuth consent at any time. We do not read or modify ad content, budgets, billing, targeting, or keywords.
Meta Marketing API
Permissions: ads_management, ads_read, business_management
Purpose: Filter invalid traffic from Facebook and Instagram advertising campaigns.
Services used:
- Read campaign metadata and performance insights for the authenticated advertiser.
- Create and manage Custom Audiences to exclude invalid traffic from retargeting.
- Send invalid traffic events via the Meta Conversions API for reporting.
User control: The user can review every exclusion and disable automated actions at any time from the MyClickShield dashboard.
Microsoft Advertising API
OAuth scope: https://ads.microsoft.com/msads.manage
Purpose: Protect Microsoft Ads campaigns from invalid traffic.
Services used:
- Read campaign metadata and performance data.
- Manage Negative Site Lists and IP exclusions for protected campaigns.
- Upload offline conversion adjustments for user-flagged invalid clicks.
User control: All changes are logged, reversible, and disabled by default until the user explicitly opts in.
Data Lifecycle & Storage
Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). OAuth refresh tokens and API credentials are stored in an encrypted secrets store and never exposed in logs or error messages.
Storage
Customer data is stored in isolated database tables with strict row-level access controls. Production databases are backed up daily and backups are encrypted with separate keys.
Retention
Click-level data is retained for the duration of the subscription plus a grace period of 30 days. Aggregated, non-identifiable statistics may be retained for longer for product analytics.
Deletion
Account deletion requests are processed within 30 days. Upon deletion, OAuth tokens are revoked, personal data is removed, and API connections to advertising platforms are terminated.
Infrastructure & Data Centers
AWS & Google Cloud
Multi-cloud infrastructure with automatic failover and geographic redundancy across US and EU regions.
Global Edge Network
300+ edge locations via Cloudflare for low-latency fraud detection worldwide.
Data Residency Options
Choose where your data is stored. EU-only processing available for European customers.
Have Security Questions?
Our security team is available to answer your questions and provide additional documentation for your compliance requirements.