Security Vulnerability Disclosure and security.txt Standards | AdCel

The Role of security.txt in Modern Infrastructure

In an era defined by rapid automation and the continuous integration of complex software stacks, maintaining a robust security posture is not merely a technical requirement but a foundational pillar of trust. AdCel, as an Intelligent Performance Platform, operates at the intersection of high-scale data processing and automated growth orchestration. To ensure the integrity of these systems, we adhere to the security.txt standard, as defined in RFC 9116. This standard provides a machine-readable and human-accessible method for security researchers to identify our vulnerability disclosure policies and contact information.

The implementation of the .well-known/security.txt file is a proactive step towards transparency. By providing a standardised path for security researchers to report potential flaws, we reduce the friction associated with vulnerability management. This alignment with global security standards ensures that AdCel remains resilient against emerging threats while fostering a collaborative environment with the global cybersecurity community.

AdCel’s Commitment to Coordinated Vulnerability Disclosure (CVD)

At AdCel, our approach to security is rooted in the principle of Coordinated Vulnerability Disclosure (CVD). We recognise that no system is entirely immune to vulnerabilities, and the expertise of independent security researchers is an invaluable asset in identifying potential risks before they can be exploited by malicious actors. Our security disclosure policy is designed to provide a clear, safe, and efficient framework for reporting and resolving security issues.

By following the guidelines outlined in our security.txt file, researchers can be assured that their reports will be handled with the utmost professionalism and urgency. Our internal security team is dedicated to reviewing every submission, validating the findings, and implementing necessary remediations in a timeline that reflects the severity of the identified risk. This commitment to CVD is a core component of our broader Trust and Transparency Framework, ensuring that our automation software remains a secure foundation for our clients’ growth engines.

Reporting Process and Communication Protocols

To maintain the confidentiality and integrity of the disclosure process, AdCel requires all security reports to be submitted through our designated channels. The primary contact method is specified within the security.txt file, typically pointing to a secure email address or a dedicated bug bounty platform. When submitting a report, researchers are encouraged to provide a detailed technical summary, including:

  • The specific component or endpoint affected within the AdCel ecosystem.
  • A step-by-step description of the proof-of-concept (PoC) required to reproduce the vulnerability.
  • The potential impact of the vulnerability on data integrity, system availability, or user privacy.
  • Any suggested remediation steps or architectural improvements.

To further protect sensitive information during the reporting phase, AdCel supports the use of PGP (Pretty Good Privacy) encryption. Our public PGP key is linked within the security.txt file, allowing researchers to encrypt their communications and ensure that vulnerability details are only accessible to authorised personnel within our security organisation.

Scope of the Security Disclosure Policy

The scope of our security disclosure policy encompasses all digital assets owned and operated by AdCel, including our core performance orchestration platform, public-facing APIs, and administrative interfaces. However, it is essential for researchers to distinguish between systems managed directly by AdCel and third-party integrations or infrastructure providers. While we take responsibility for the security of our proprietary software, vulnerabilities found in third-party services should be reported to the respective vendors.

Activities that are strictly prohibited under this policy include:

  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks that aim to disrupt the availability of our services.
  • Social engineering, phishing, or physical security attacks against AdCel employees or data centres.
  • Unauthorised access to, or modification of, user data.
  • Exploiting vulnerabilities for financial gain or any form of extortion.

Researchers are expected to act in good faith, avoiding any actions that could cause harm to AdCel, its clients, or its partners. Adhering to these boundaries ensures that the research remains ethical and legally protected.

Safe Harbour and Legal Protections

AdCel is committed to providing a ‘Safe Harbour’ for security researchers who discover and report vulnerabilities in compliance with our policies. We will not pursue legal action against individuals who conduct security research and disclose vulnerabilities in a manner that aligns with the guidelines set forth in our security.txt and disclosure policy. We view these researchers as partners in our mission to build a more secure and automated digital advertising ecosystem.

This protection is contingent upon the researcher’s adherence to ethical standards, including the avoidance of data privacy violations and the commitment to give AdCel a reasonable period to address the vulnerability before any public disclosure is made. By formalising this relationship, we aim to eliminate the legal ambiguity that often surrounds security research, encouraging a more open and secure environment for everyone involved in the performance marketing industry.

Response Timelines and Remediation Standards

Efficiency in vulnerability management is critical to minimising the window of exposure. AdCel strives to acknowledge all valid security reports within 48 to 72 business hours. Following the initial acknowledgement, our engineering and security teams conduct a thorough investigation to determine the root cause and assess the risk level based on the Common Vulnerability Scoring System (CVSS).

The timeline for remediation is prioritised based on the severity of the flaw. Critical vulnerabilities that pose an immediate risk to data security or system stability are addressed with the highest priority, often resulting in a patch or mitigation within days. Lower-risk issues are integrated into our standard development lifecycle and resolved in subsequent platform updates. Throughout this process, we maintain open lines of communication with the reporting researcher, providing updates on the status of the fix and, where appropriate, acknowledging their contribution to our platform’s security.

Integrating Security into the Growth Lifecycle

The implementation of security.txt is not an isolated task but part of a holistic approach to security-by-design. As we continue to develop autonomous performance orchestration tools, security must be baked into the automation logic itself. By standardising how we handle external security feedback, we ensure that our growth engines scale not just with speed and efficiency, but with the highest standards of technical integrity. This rigorous approach to security allows our partners to focus on scaling their operations, confident that the underlying infrastructure is monitored, protected, and transparently managed.

© 2025 AdCel. All rights reserved.