Security is a promise, not a feature. This Security Policy describes how eFind protects the data and systems entrusted to us, the organizational and technical measures we rely on, and the responsibilities we share with the Advertisers, Publishers, and other customers who use the Services. We aim to be honest about what we do today and clear about where we are still building.
This Security Policy explains the program eFind runs to keep the Services, the data they hold, and the infrastructure they run on secure. It is written for two audiences at once. For enterprise customers and their security teams, it is a clear account of the controls we operate and the commitments we stand behind, so that you can evaluate eFind with confidence. For every other reader, it is a plain-English description of how we approach the hard, continuous work of protecting information. We have tried to describe our program accurately rather than aspirationally. Where a control is a goal we are working toward rather than a state we have fully reached, we say so.
Security is never finished. Threats change, our Services grow, and the measures below are reviewed and improved on a continuous basis. This document therefore describes a living program, and the specific technologies and procedures we use will evolve while the commitments and principles behind them remain stable.
This Security Policy applies to the Services as defined in the Master Definitions, including the eFind Ads advertising platform, our websites, applications, APIs, and the production systems and infrastructure that operate them. It covers the ways eFind protects Personal Information, Confidential Information, Advertiser Content, Publisher Content, and the operational data generated by the Services, whether that data is in transit across networks or at rest in our systems.
This document describes eFind's own security program and the measures we apply. It is not a substitute for the contractual security commitments in the Data Processing Addendum, which control where they address the same subject for Personal Information that eFind Processes on a customer's behalf. Where this Security Policy and the Data Processing Addendum both speak to a technical or organizational measure, the two are meant to be read together, and the Data Processing Addendum governs the legal obligations that flow from the Processing relationship.
This Security Policy applies to eFind, to our personnel, and to the Sub-processors and vendors we hold to security standards on our behalf. It also describes responsibilities that fall to Advertisers, Publishers, developers, and other customers, because security is a shared undertaking that no single party can deliver alone. When you use the Services, you rely on the measures we describe here, and we rely on you to protect your own credentials, systems, and integrations as set out in the shared-responsibility section below.
Capitalized terms used in this document, such as Personal Information, Confidential Information, Services, Sub-processor, Advertiser, Publisher, and Applicable Law, have the meanings given in the Master Definitions. A few terms are specific to this document. A Security Incident means a confirmed or reasonably suspected event that compromises the confidentiality, integrity, or availability of the Services or of data they hold, including unauthorized access to, acquisition of, or disclosure of Personal Information. A Vulnerability means a weakness in software, configuration, or process that could be exploited to cause a Security Incident. Recognized Frameworks means widely used information-security and privacy standards and control catalogs, such as those published by the International Organization for Standardization, the American Institute of Certified Public Accountants, and the National Institute of Standards and Technology, that eFind uses as reference points for its program.
eFind builds an advertising platform that touches large volumes of data about businesses and the people they reach. That responsibility shapes how we think about security. We treat security as a property of the whole system rather than a bolt-on, and we design for it from the first line of code and the first architectural decision. The principles below guide every control described later in this document.
We do not rely on any single control to keep data safe. We layer protections so that the failure of one measure does not expose data, combining network controls, application controls, identity controls, encryption, monitoring, and human review. If an attacker gets past one layer, the next should slow, contain, or reveal them.
People and systems get the minimum access they need to do their work, and no more. Access is granted for a reason, tied to a role, and removed when the reason ends. This principle applies to our personnel, to the services that make up the platform, and to the automated processes that run it.
We aim to make the secure path the easy path. New features are designed with security and privacy considered from the start, sensible protections are turned on by default rather than left to be configured, and we prefer safe defaults over settings that trade protection for convenience.
We plan for the possibility that something will go wrong. We segment systems, limit the blast radius of any single compromise, log activity so that we can reconstruct events, and rehearse our response so that when an incident happens we act quickly and calmly rather than improvising.
We would rather describe our program accurately than overstate it. Security claims that outrun reality erode the very trust they are meant to build. Where we are still maturing a control, we treat that as an aspiration we are actively pursuing, not a promise we have already kept.
A security program is only as strong as the accountability behind it. eFind runs its program under clear ownership, documented policies, and a risk-management process that ties day-to-day decisions to the level of protection our customers expect.
Responsibility for information security sits with eFind's security leadership, which reports into senior management and coordinates with the eFind Office of Trust and Legal. Security is not treated as the job of one team alone. Engineering, operations, and product teams each carry responsibility for the security of what they build and run, and security leadership sets the standards, reviews the risks, and holds those teams to account.
eFind maintains a set of internal security policies and standards that translate the principles in this document into specific rules for our personnel and systems. These cover areas such as acceptable use of company systems, access control, data classification and handling, secure development, change management, logging, incident response, and business continuity. Policies are documented, made available to the personnel they apply to, and reviewed on a regular cycle so that they keep pace with how the Services actually work.
We manage security through risk rather than through checklists alone. eFind identifies the assets that matter, assesses the threats and vulnerabilities that could affect them, and evaluates the likelihood and impact of the resulting risks. We then decide how to treat each risk, whether by adding a control, accepting the risk at a documented and appropriate level, transferring it, or avoiding the activity that creates it. Significant risks are tracked, assigned an owner, and reviewed by security leadership so that decisions are made deliberately and revisited as circumstances change.
eFind designs its program with reference to Recognized Frameworks so that our controls map to concepts security professionals already know and trust. We use these frameworks as a common vocabulary and as a benchmark for completeness, checking our controls against established control catalogs rather than inventing our approach from scratch.
Alignment with a Recognized Framework is not the same as certification against it. Where eFind states that it aligns with a framework, we mean that we use it as a design reference and aspire to its control objectives. We will describe any formal certifications or independent attestations we hold, and their scope, separately and accurately rather than implying them here.
Technology alone does not make an organization secure. The people who build and operate the Services, and the way their work is structured, are among the most important controls we have.
Before personnel are given access to systems that hold Personal Information or Confidential Information, eFind conducts screening appropriate to the role and permitted by Applicable Law, which may include identity verification and background checks. Access to sensitive systems is reserved for personnel who have completed the screening required for that level of access.
Every member of our personnel receives security and privacy training when they join and on a recurring basis afterward. Training covers how to recognize social-engineering and phishing attempts, how to handle Personal Information and Confidential Information safely, how to report a suspected Security Incident, and the specific responsibilities of their role. Personnel who build software receive additional training on secure development practices.
Access to systems and data is granted on a need-to-know basis and scoped to the least privilege required for a person's role. Sensitive operations are structured so that no single individual can complete a high-risk action unchecked. Where appropriate, we separate duties so that the person who requests a change is not the only person who approves or deploys it, reducing the chance that a mistake or a malicious act goes unnoticed.
Personnel and contractors are bound by confidentiality obligations that survive the end of their engagement. Everyone who handles Personal Information or Confidential Information is required to keep it confidential, to use it only for authorized purposes, and to follow the handling rules set out in our internal policies. These obligations are reflected in the Confidential Information provisions of our Agreements and in the confidentiality commitments in the Data Processing Addendum.
When personnel leave eFind or change roles, we revoke the access they no longer need in a timely way, recover company assets, and confirm that credentials tied to their access are disabled. Offboarding is treated as a security event, not just an administrative one.
The technical controls below protect data as it moves and as it rests, harden the systems that process it, and give us the visibility to detect problems. These controls work together, and each is one layer of the defense-in-depth approach described earlier.
eFind encrypts Personal Information and other sensitive data in transit over public networks using current, industry-accepted transport encryption. Connections to our websites, applications, and APIs are protected with strong cryptographic protocols, and we work to disable weak protocols and cipher suites as they age out of safe use. Internal traffic between the components that make up the Services is likewise protected where it crosses trust boundaries.
Personal Information and other sensitive data are encrypted at rest in the storage systems that hold them, using strong, industry-accepted algorithms. Encryption at rest protects data against exposure if the underlying storage media are lost, stolen, or improperly accessed at the physical or infrastructure layer.
Encryption is only as strong as the way its keys are managed. eFind protects cryptographic keys through controlled generation, storage, rotation, and retirement. Keys are held in protected key-management facilities, access to keys is restricted to the systems and personnel that require it, and keys are rotated on a defined schedule and when circumstances warrant. We separate the management of keys from the data they protect so that access to one does not automatically grant access to the other.
eFind segments its networks so that systems are grouped by function and sensitivity rather than sitting on a single flat network. Firewalls and equivalent access controls restrict traffic between segments to what is necessary, and the systems that hold the most sensitive data are placed in more restricted zones. Segmentation limits how far an attacker who reaches one part of the environment can move, and it makes unusual cross-segment traffic easier to notice.
Security is built into how we write software, not inspected in at the end. Our development lifecycle incorporates security requirements at the design stage, secure coding practices during development, and testing before release. Developers work from documented secure-development standards, and significant new features receive a security and privacy review proportionate to their risk.
Changes to the Services move through a controlled process. Code is reviewed before it is merged, changes are tracked, and deployments to production follow a defined change-management path with the ability to roll back. Reviewing code and gating changes catches many defects, including security defects, before they reach customers.
eFind runs a vulnerability-management process to find, prioritize, and fix weaknesses in our software, dependencies, and infrastructure. We use automated scanning and dependency analysis to surface known vulnerabilities, we prioritize them by severity and exposure, and we apply patches and mitigations within timeframes that reflect their risk. High-severity issues are handled with urgency; lower-severity issues are scheduled and tracked to resolution.
eFind conducts security testing of the Services, including penetration testing that probes our systems the way an attacker would. Testing may be performed by qualified internal personnel or by independent third parties, and the findings feed back into our vulnerability-management and remediation process. We treat testing as a routine part of the program rather than a one-time event.
eFind records security-relevant events across the Services, including access to sensitive systems and administrative actions. Logs are collected centrally, protected against tampering, and retained for a period appropriate to their purpose. We monitor for anomalies and known-bad activity, and we use automated detection to alert our team to potential Security Incidents so that we can investigate and respond quickly. Monitoring exists both to catch problems early and to let us reconstruct what happened if an incident occurs.
Controlling who can reach what is one of the most consequential parts of security. eFind manages identity and access for its own personnel and provides customers with the tools to manage access to their Accounts.
Access to eFind systems and to customer Accounts is protected by authentication controls appropriate to the sensitivity of what is being accessed. We enforce credential-strength requirements, protect stored credentials using accepted one-way hashing techniques, and apply protections against automated guessing and credential-stuffing attacks.
eFind uses multi-factor authentication to protect access to sensitive internal systems, so that a stolen password alone is not enough to gain entry. We also support and encourage multi-factor authentication for customer Accounts, and we recommend that every Advertiser, Publisher, and Authorized User enable it. Where the Services offer it, turning on multi-factor authentication is one of the single most effective steps a customer can take to protect an Account.
Access rights are reviewed on a periodic basis to confirm that they are still appropriate. During these reviews we remove access that is no longer needed, correct any excessive privileges, and verify that access to the most sensitive systems remains limited to the personnel who require it. Access reviews are how least privilege stays true over time rather than drifting as roles change.
Administrative and other highly privileged access is granted sparingly, monitored closely, and, where practical, made available only when needed rather than standing open at all times. Actions taken with privileged access are logged so that they can be reviewed.
The safest data is the data we do not hold. eFind applies data minimization as a security control, collecting and retaining Personal Information only as needed to provide and improve the Services and to meet legal obligations. We classify data by sensitivity and apply handling rules that match the classification, so that the most sensitive information receives the strongest protection.
We retain Personal Information for no longer than necessary for the purposes for which it was collected, unless a longer period is required or permitted by Applicable Law, and we dispose of data securely when it is no longer needed. Where we can accomplish a purpose with Aggregated Data or de-identified data instead of Personal Information, we prefer to do so. The full detail of what we collect, why, how long we keep it, and the rights available to individuals is set out in the Privacy Policy and the related privacy notices.
Minimizing and classifying data is a security decision as much as a privacy one. Every field we choose not to collect, and every record we securely delete when it is no longer needed, is one less thing an attacker could ever reach.
eFind relies on carefully chosen vendors and Sub-processors to help deliver the Services, and we hold them to security standards consistent with our own. Before we engage a vendor or Sub-processor that will handle Personal Information or Confidential Information, we conduct security due diligence proportionate to the risk, which may include reviewing their security practices, certifications, and track record.
We put contracts in place that require appropriate technical and organizational security measures, confidentiality, and cooperation in the event of a Security Incident. For Sub-processors that Process Personal Information on a customer's behalf, we flow down data-protection obligations consistent with the Data Processing Addendum, and we remain responsible to our customers for the performance of those Sub-processors. We monitor our vendors and Sub-processors over time rather than treating due diligence as a one-time gate, and we maintain the ability to change a vendor whose security no longer meets our standards.
Despite strong preventive controls, security incidents can still happen anywhere. What separates a well-run program from a poorly run one is how quickly and honestly it detects, contains, and communicates. eFind maintains a documented incident-response process so that we act consistently under pressure.
We detect potential Security Incidents through the monitoring, logging, and threat-detection controls described above, through alerts from automated systems, through reports from our personnel, and through reports from customers and outside researchers. Every credible report is triaged, and suspected incidents are escalated to the personnel responsible for response.
Our incident-response process moves through defined phases: identifying and confirming the incident, containing it to limit harm, eradicating the cause, recovering affected systems, and reviewing what happened afterward. During a live incident, a coordinated response team preserves evidence, works to stop ongoing harm, and keeps a record of the actions taken. After the incident is resolved, we conduct a review to understand root causes and to strengthen our controls so that a similar incident is less likely to recur.
When a Security Incident affects Personal Information that eFind Processes on behalf of a customer, we will notify the affected customer without undue delay after becoming aware of it, consistent with the notification obligations in the Data Processing Addendum and with Applicable Law. Our notice will describe the nature of the incident, the categories of data and individuals affected to the extent known, the likely consequences, and the measures we have taken or propose to take, and it will be updated as more becomes known. Where eFind acts as a Controller of Personal Information, or where Applicable Law requires notice to individuals or to a regulator, we will provide that notice within the required timeframes. We coordinate with affected customers on communications so that, wherever practical, our respective notices are consistent.
The precise notification timelines, content, and responsibilities for Personal Information that eFind Processes on a customer's behalf are governed by the Data Processing Addendum. Where this section and the Data Processing Addendum address the same obligation, the Data Processing Addendum controls.
Availability is part of security. eFind maintains business-continuity and disaster-recovery arrangements designed to keep the Services running and to bring them back quickly if a serious disruption occurs. We back up critical data on a regular schedule, protect those backups, and test our ability to restore from them so that a backup we cannot restore is not treated as a backup at all.
Our infrastructure is built with resilience in mind, using redundancy so that the failure of a single component does not take down the Services. We maintain plans for responding to events such as infrastructure failures, natural disasters, and other disruptions covered by the concept of Force Majeure, and we review and exercise those plans so that our people know their roles before they are needed. Our recovery objectives are set to balance the speed of restoration against the integrity of the data being restored.
The Services run on infrastructure hosted in facilities that provide strong physical and environmental protections. eFind relies on infrastructure providers whose data centers restrict physical access to authorized personnel, monitor their facilities, and protect equipment against environmental hazards such as fire, flooding, and power loss through measures like access controls, surveillance, fire suppression, climate control, and backup power. We include the physical-security posture of our infrastructure providers in the due diligence we apply to vendors and Sub-processors.
Within eFind's own corporate environment, we apply physical-security measures appropriate to protecting the systems and information used by our personnel, and we require that devices used to access sensitive systems meet our security requirements. Physical security and logical security reinforce each other, and we treat them as parts of one program.
We welcome the help of the security community. If you are a researcher, a customer, or anyone else who discovers a potential Vulnerability in the Services, we want to hear from you, and we would rather learn about a weakness from you than from an attacker.
Please report suspected Vulnerabilities to us at support@efind.com, with enough detail for us to reproduce and understand the issue, and mark your message as a security report. You can also reach our team by phone at 1-214-444-8126. We will acknowledge credible reports, investigate them, and work to remediate confirmed Vulnerabilities in a timeframe that reflects their severity.
We ask that researchers act in good faith: give us a reasonable opportunity to investigate and fix an issue before disclosing it publicly, avoid accessing or modifying data that is not your own, avoid degrading the Services or the experience of other users, and stay within the bounds of Applicable Law and the Acceptable Use Policy. Testing that involves denial-of-service, spam, social engineering of our personnel or customers, or physical intrusion is not authorized. When researchers report in good faith and follow these guidelines, we will not pursue action against them for the research itself, and we will treat their reports as a valued contribution to the security of the Services.
Security of the Services is a partnership. eFind is responsible for securing the platform, the infrastructure it runs on, and the measures described in this document. Customers are responsible for how they use the Services and for the parts of the environment under their control. Neither party can deliver security alone, and gaps most often appear at the boundary between the two. The table below summarizes the division; the detail follows.
| Area | eFind is responsible for | The customer is responsible for |
|---|---|---|
| Platform and infrastructure | Securing the Services, hosting infrastructure, and the controls in this Policy | Using the Services in line with the Agreements and Policies |
| Account access | Providing authentication and multi-factor options | Protecting credentials and enabling multi-factor authentication |
| Configuration | Offering secure defaults and access controls | Configuring settings, roles, and permissions appropriately |
| Integrations and API keys | Securing the APIs and issuing keys | Safeguarding API keys and securing integrations |
| Customer content and systems | Protecting data within the Services | Securing Advertiser and Publisher systems, Landing Pages, and properties |
You are responsible for keeping the credentials that access your Account confidential, for choosing strong and unique passwords, for enabling multi-factor authentication where it is offered, and for making sure that only trusted Authorized Users can reach your Account. Many of the most damaging incidents affecting online services begin with a credential that was reused, shared, or left unprotected. Treat your credentials as keys to your data.
You are responsible for configuring the settings, roles, and permissions available in the Services in a way that fits your security needs, and for keeping the Devices and systems you use to access the Services patched and protected. We provide controls and sensible defaults; you decide how to apply them to your organization.
If you connect to the Services through an API, integrate a Publisher Property, deploy Conversion Tracking, or otherwise build on top of the platform, you are responsible for securing those integrations. This includes protecting API keys and other secrets, storing them securely rather than embedding them where they can be discovered, rotating them when they may have been exposed, restricting their scope, and monitoring their use. An exposed API key can let someone act as you, so treat keys with the same care as passwords.
If you believe your Account has been compromised, or you notice activity that concerns you, tell us promptly at support@efind.com or 1-214-444-8126 so that we can help you respond. Quick reporting is one of the most valuable things a customer can do, because it lets us contain problems before they spread.
eFind reviews this Security Policy and the program behind it on a regular basis, and additionally when there is a significant change in our Services, our infrastructure, the threat landscape, or Applicable Law. Reviews are how we keep the words on this page aligned with the controls we actually operate. When we make material changes, we will post the updated policy on this page, and we will communicate significant changes through the means described in our Agreements and Policies. Because security is a continuous practice, we expect this document to change over time, and each version supersedes the ones before it.
Building Technology People Can Trust.
© 2026 eFind. All rights reserved.