e Find eFind Ads
Why eFind Ads
Solutions expand_more
Leads Display Search Video Affiliates Earn With Ads
Resources expand_more
All docs For advertisers For publishers Support center
FAQ Contact
1-214-444-8126 Sign in Start now
Why eFind Ads chevron_right
Leads Display Search Video Affiliates Earn With Ads
All docs For advertisers For publishers Support center
FAQ chevron_right Contact chevron_right
Start now Sign in phone 1-214-444-8126
Trust Framework

Security Policy

Security is a promise, not a feature. This Security Policy describes how eFind protects the data and systems entrusted to us, the organizational and technical measures we rely on, and the responsibilities we share with the Advertisers, Publishers, and other customers who use the Services. We aim to be honest about what we do today and clear about where we are still building.

Purpose

This Security Policy explains the program eFind runs to keep the Services, the data they hold, and the infrastructure they run on secure. It is written for two audiences at once. For enterprise customers and their security teams, it is a clear account of the controls we operate and the commitments we stand behind, so that you can evaluate eFind with confidence. For every other reader, it is a plain-English description of how we approach the hard, continuous work of protecting information. We have tried to describe our program accurately rather than aspirationally. Where a control is a goal we are working toward rather than a state we have fully reached, we say so.

Security is never finished. Threats change, our Services grow, and the measures below are reviewed and improved on a continuous basis. This document therefore describes a living program, and the specific technologies and procedures we use will evolve while the commitments and principles behind them remain stable.

Scope

This Security Policy applies to the Services as defined in the Master Definitions, including the eFind Ads advertising platform, our websites, applications, APIs, and the production systems and infrastructure that operate them. It covers the ways eFind protects Personal Information, Confidential Information, Advertiser Content, Publisher Content, and the operational data generated by the Services, whether that data is in transit across networks or at rest in our systems.

This document describes eFind's own security program and the measures we apply. It is not a substitute for the contractual security commitments in the Data Processing Addendum, which control where they address the same subject for Personal Information that eFind Processes on a customer's behalf. Where this Security Policy and the Data Processing Addendum both speak to a technical or organizational measure, the two are meant to be read together, and the Data Processing Addendum governs the legal obligations that flow from the Processing relationship.

Who It Applies To

This Security Policy applies to eFind, to our personnel, and to the Sub-processors and vendors we hold to security standards on our behalf. It also describes responsibilities that fall to Advertisers, Publishers, developers, and other customers, because security is a shared undertaking that no single party can deliver alone. When you use the Services, you rely on the measures we describe here, and we rely on you to protect your own credentials, systems, and integrations as set out in the shared-responsibility section below.

Definitions

Capitalized terms used in this document, such as Personal Information, Confidential Information, Services, Sub-processor, Advertiser, Publisher, and Applicable Law, have the meanings given in the Master Definitions. A few terms are specific to this document. A Security Incident means a confirmed or reasonably suspected event that compromises the confidentiality, integrity, or availability of the Services or of data they hold, including unauthorized access to, acquisition of, or disclosure of Personal Information. A Vulnerability means a weakness in software, configuration, or process that could be exploited to cause a Security Incident. Recognized Frameworks means widely used information-security and privacy standards and control catalogs, such as those published by the International Organization for Standardization, the American Institute of Certified Public Accountants, and the National Institute of Standards and Technology, that eFind uses as reference points for its program.

Our Security Philosophy

eFind builds an advertising platform that touches large volumes of data about businesses and the people they reach. That responsibility shapes how we think about security. We treat security as a property of the whole system rather than a bolt-on, and we design for it from the first line of code and the first architectural decision. The principles below guide every control described later in this document.

Defense in Depth

We do not rely on any single control to keep data safe. We layer protections so that the failure of one measure does not expose data, combining network controls, application controls, identity controls, encryption, monitoring, and human review. If an attacker gets past one layer, the next should slow, contain, or reveal them.

Least Privilege by Default

People and systems get the minimum access they need to do their work, and no more. Access is granted for a reason, tied to a role, and removed when the reason ends. This principle applies to our personnel, to the services that make up the platform, and to the automated processes that run it.

Secure by Design and by Default

We aim to make the secure path the easy path. New features are designed with security and privacy considered from the start, sensible protections are turned on by default rather than left to be configured, and we prefer safe defaults over settings that trade protection for convenience.

Assume Breach and Contain

We plan for the possibility that something will go wrong. We segment systems, limit the blast radius of any single compromise, log activity so that we can reconstruct events, and rehearse our response so that when an incident happens we act quickly and calmly rather than improvising.

Honesty Over Marketing

We would rather describe our program accurately than overstate it. Security claims that outrun reality erode the very trust they are meant to build. Where we are still maturing a control, we treat that as an aspiration we are actively pursuing, not a promise we have already kept.

Program Governance

A security program is only as strong as the accountability behind it. eFind runs its program under clear ownership, documented policies, and a risk-management process that ties day-to-day decisions to the level of protection our customers expect.

Ownership and Accountability

Responsibility for information security sits with eFind's security leadership, which reports into senior management and coordinates with the eFind Office of Trust and Legal. Security is not treated as the job of one team alone. Engineering, operations, and product teams each carry responsibility for the security of what they build and run, and security leadership sets the standards, reviews the risks, and holds those teams to account.

Security Policies and Standards

eFind maintains a set of internal security policies and standards that translate the principles in this document into specific rules for our personnel and systems. These cover areas such as acceptable use of company systems, access control, data classification and handling, secure development, change management, logging, incident response, and business continuity. Policies are documented, made available to the personnel they apply to, and reviewed on a regular cycle so that they keep pace with how the Services actually work.

Risk Management

We manage security through risk rather than through checklists alone. eFind identifies the assets that matter, assesses the threats and vulnerabilities that could affect them, and evaluates the likelihood and impact of the resulting risks. We then decide how to treat each risk, whether by adding a control, accepting the risk at a documented and appropriate level, transferring it, or avoiding the activity that creates it. Significant risks are tracked, assigned an owner, and reviewed by security leadership so that decisions are made deliberately and revisited as circumstances change.

Alignment with Recognized Frameworks

eFind designs its program with reference to Recognized Frameworks so that our controls map to concepts security professionals already know and trust. We use these frameworks as a common vocabulary and as a benchmark for completeness, checking our controls against established control catalogs rather than inventing our approach from scratch.

Note

Alignment with a Recognized Framework is not the same as certification against it. Where eFind states that it aligns with a framework, we mean that we use it as a design reference and aspire to its control objectives. We will describe any formal certifications or independent attestations we hold, and their scope, separately and accurately rather than implying them here.

Organizational Measures

Technology alone does not make an organization secure. The people who build and operate the Services, and the way their work is structured, are among the most important controls we have.

Personnel Screening

Before personnel are given access to systems that hold Personal Information or Confidential Information, eFind conducts screening appropriate to the role and permitted by Applicable Law, which may include identity verification and background checks. Access to sensitive systems is reserved for personnel who have completed the screening required for that level of access.

Security Training and Awareness

Every member of our personnel receives security and privacy training when they join and on a recurring basis afterward. Training covers how to recognize social-engineering and phishing attempts, how to handle Personal Information and Confidential Information safely, how to report a suspected Security Incident, and the specific responsibilities of their role. Personnel who build software receive additional training on secure development practices.

Least-Privilege Access and Separation of Duties

Access to systems and data is granted on a need-to-know basis and scoped to the least privilege required for a person's role. Sensitive operations are structured so that no single individual can complete a high-risk action unchecked. Where appropriate, we separate duties so that the person who requests a change is not the only person who approves or deploys it, reducing the chance that a mistake or a malicious act goes unnoticed.

Confidentiality Obligations

Personnel and contractors are bound by confidentiality obligations that survive the end of their engagement. Everyone who handles Personal Information or Confidential Information is required to keep it confidential, to use it only for authorized purposes, and to follow the handling rules set out in our internal policies. These obligations are reflected in the Confidential Information provisions of our Agreements and in the confidentiality commitments in the Data Processing Addendum.

Offboarding

When personnel leave eFind or change roles, we revoke the access they no longer need in a timely way, recover company assets, and confirm that credentials tied to their access are disabled. Offboarding is treated as a security event, not just an administrative one.

Technical Measures

The technical controls below protect data as it moves and as it rests, harden the systems that process it, and give us the visibility to detect problems. These controls work together, and each is one layer of the defense-in-depth approach described earlier.

Encryption in Transit

eFind encrypts Personal Information and other sensitive data in transit over public networks using current, industry-accepted transport encryption. Connections to our websites, applications, and APIs are protected with strong cryptographic protocols, and we work to disable weak protocols and cipher suites as they age out of safe use. Internal traffic between the components that make up the Services is likewise protected where it crosses trust boundaries.

Encryption at Rest

Personal Information and other sensitive data are encrypted at rest in the storage systems that hold them, using strong, industry-accepted algorithms. Encryption at rest protects data against exposure if the underlying storage media are lost, stolen, or improperly accessed at the physical or infrastructure layer.

Key Management

Encryption is only as strong as the way its keys are managed. eFind protects cryptographic keys through controlled generation, storage, rotation, and retirement. Keys are held in protected key-management facilities, access to keys is restricted to the systems and personnel that require it, and keys are rotated on a defined schedule and when circumstances warrant. We separate the management of keys from the data they protect so that access to one does not automatically grant access to the other.

Network Segmentation and Firewalls

eFind segments its networks so that systems are grouped by function and sensitivity rather than sitting on a single flat network. Firewalls and equivalent access controls restrict traffic between segments to what is necessary, and the systems that hold the most sensitive data are placed in more restricted zones. Segmentation limits how far an attacker who reaches one part of the environment can move, and it makes unusual cross-segment traffic easier to notice.

Secure Software Development Lifecycle

Security is built into how we write software, not inspected in at the end. Our development lifecycle incorporates security requirements at the design stage, secure coding practices during development, and testing before release. Developers work from documented secure-development standards, and significant new features receive a security and privacy review proportionate to their risk.

Code Review and Change Management

Changes to the Services move through a controlled process. Code is reviewed before it is merged, changes are tracked, and deployments to production follow a defined change-management path with the ability to roll back. Reviewing code and gating changes catches many defects, including security defects, before they reach customers.

Vulnerability Management and Patching

eFind runs a vulnerability-management process to find, prioritize, and fix weaknesses in our software, dependencies, and infrastructure. We use automated scanning and dependency analysis to surface known vulnerabilities, we prioritize them by severity and exposure, and we apply patches and mitigations within timeframes that reflect their risk. High-severity issues are handled with urgency; lower-severity issues are scheduled and tracked to resolution.

Penetration Testing

eFind conducts security testing of the Services, including penetration testing that probes our systems the way an attacker would. Testing may be performed by qualified internal personnel or by independent third parties, and the findings feed back into our vulnerability-management and remediation process. We treat testing as a routine part of the program rather than a one-time event.

Logging, Monitoring, and Threat Detection

eFind records security-relevant events across the Services, including access to sensitive systems and administrative actions. Logs are collected centrally, protected against tampering, and retained for a period appropriate to their purpose. We monitor for anomalies and known-bad activity, and we use automated detection to alert our team to potential Security Incidents so that we can investigate and respond quickly. Monitoring exists both to catch problems early and to let us reconstruct what happened if an incident occurs.

Identity and Access Management

Controlling who can reach what is one of the most consequential parts of security. eFind manages identity and access for its own personnel and provides customers with the tools to manage access to their Accounts.

Authentication

Access to eFind systems and to customer Accounts is protected by authentication controls appropriate to the sensitivity of what is being accessed. We enforce credential-strength requirements, protect stored credentials using accepted one-way hashing techniques, and apply protections against automated guessing and credential-stuffing attacks.

Multi-Factor Authentication

eFind uses multi-factor authentication to protect access to sensitive internal systems, so that a stolen password alone is not enough to gain entry. We also support and encourage multi-factor authentication for customer Accounts, and we recommend that every Advertiser, Publisher, and Authorized User enable it. Where the Services offer it, turning on multi-factor authentication is one of the single most effective steps a customer can take to protect an Account.

Access Reviews

Access rights are reviewed on a periodic basis to confirm that they are still appropriate. During these reviews we remove access that is no longer needed, correct any excessive privileges, and verify that access to the most sensitive systems remains limited to the personnel who require it. Access reviews are how least privilege stays true over time rather than drifting as roles change.

Privileged Access

Administrative and other highly privileged access is granted sparingly, monitored closely, and, where practical, made available only when needed rather than standing open at all times. Actions taken with privileged access are logged so that they can be reviewed.

Data Protection and Data Minimization

The safest data is the data we do not hold. eFind applies data minimization as a security control, collecting and retaining Personal Information only as needed to provide and improve the Services and to meet legal obligations. We classify data by sensitivity and apply handling rules that match the classification, so that the most sensitive information receives the strongest protection.

We retain Personal Information for no longer than necessary for the purposes for which it was collected, unless a longer period is required or permitted by Applicable Law, and we dispose of data securely when it is no longer needed. Where we can accomplish a purpose with Aggregated Data or de-identified data instead of Personal Information, we prefer to do so. The full detail of what we collect, why, how long we keep it, and the rights available to individuals is set out in the Privacy Policy and the related privacy notices.

Why this matters

Minimizing and classifying data is a security decision as much as a privacy one. Every field we choose not to collect, and every record we securely delete when it is no longer needed, is one less thing an attacker could ever reach.

Vendor and Sub-processor Security

eFind relies on carefully chosen vendors and Sub-processors to help deliver the Services, and we hold them to security standards consistent with our own. Before we engage a vendor or Sub-processor that will handle Personal Information or Confidential Information, we conduct security due diligence proportionate to the risk, which may include reviewing their security practices, certifications, and track record.

We put contracts in place that require appropriate technical and organizational security measures, confidentiality, and cooperation in the event of a Security Incident. For Sub-processors that Process Personal Information on a customer's behalf, we flow down data-protection obligations consistent with the Data Processing Addendum, and we remain responsible to our customers for the performance of those Sub-processors. We monitor our vendors and Sub-processors over time rather than treating due diligence as a one-time gate, and we maintain the ability to change a vendor whose security no longer meets our standards.

Incident Response and Breach Notification

Despite strong preventive controls, security incidents can still happen anywhere. What separates a well-run program from a poorly run one is how quickly and honestly it detects, contains, and communicates. eFind maintains a documented incident-response process so that we act consistently under pressure.

How We Detect

We detect potential Security Incidents through the monitoring, logging, and threat-detection controls described above, through alerts from automated systems, through reports from our personnel, and through reports from customers and outside researchers. Every credible report is triaged, and suspected incidents are escalated to the personnel responsible for response.

How We Respond

Our incident-response process moves through defined phases: identifying and confirming the incident, containing it to limit harm, eradicating the cause, recovering affected systems, and reviewing what happened afterward. During a live incident, a coordinated response team preserves evidence, works to stop ongoing harm, and keeps a record of the actions taken. After the incident is resolved, we conduct a review to understand root causes and to strengthen our controls so that a similar incident is less likely to recur.

How We Notify

When a Security Incident affects Personal Information that eFind Processes on behalf of a customer, we will notify the affected customer without undue delay after becoming aware of it, consistent with the notification obligations in the Data Processing Addendum and with Applicable Law. Our notice will describe the nature of the incident, the categories of data and individuals affected to the extent known, the likely consequences, and the measures we have taken or propose to take, and it will be updated as more becomes known. Where eFind acts as a Controller of Personal Information, or where Applicable Law requires notice to individuals or to a regulator, we will provide that notice within the required timeframes. We coordinate with affected customers on communications so that, wherever practical, our respective notices are consistent.

Important

The precise notification timelines, content, and responsibilities for Personal Information that eFind Processes on a customer's behalf are governed by the Data Processing Addendum. Where this section and the Data Processing Addendum address the same obligation, the Data Processing Addendum controls.

Business Continuity and Disaster Recovery

Availability is part of security. eFind maintains business-continuity and disaster-recovery arrangements designed to keep the Services running and to bring them back quickly if a serious disruption occurs. We back up critical data on a regular schedule, protect those backups, and test our ability to restore from them so that a backup we cannot restore is not treated as a backup at all.

Our infrastructure is built with resilience in mind, using redundancy so that the failure of a single component does not take down the Services. We maintain plans for responding to events such as infrastructure failures, natural disasters, and other disruptions covered by the concept of Force Majeure, and we review and exercise those plans so that our people know their roles before they are needed. Our recovery objectives are set to balance the speed of restoration against the integrity of the data being restored.

Physical and Environmental Security

The Services run on infrastructure hosted in facilities that provide strong physical and environmental protections. eFind relies on infrastructure providers whose data centers restrict physical access to authorized personnel, monitor their facilities, and protect equipment against environmental hazards such as fire, flooding, and power loss through measures like access controls, surveillance, fire suppression, climate control, and backup power. We include the physical-security posture of our infrastructure providers in the due diligence we apply to vendors and Sub-processors.

Within eFind's own corporate environment, we apply physical-security measures appropriate to protecting the systems and information used by our personnel, and we require that devices used to access sensitive systems meet our security requirements. Physical security and logical security reinforce each other, and we treat them as parts of one program.

Responsible Disclosure and Vulnerability Reporting

We welcome the help of the security community. If you are a researcher, a customer, or anyone else who discovers a potential Vulnerability in the Services, we want to hear from you, and we would rather learn about a weakness from you than from an attacker.

How to Report

Please report suspected Vulnerabilities to us at support@efind.com, with enough detail for us to reproduce and understand the issue, and mark your message as a security report. You can also reach our team by phone at 1-214-444-8126. We will acknowledge credible reports, investigate them, and work to remediate confirmed Vulnerabilities in a timeframe that reflects their severity.

Good-Faith Research

We ask that researchers act in good faith: give us a reasonable opportunity to investigate and fix an issue before disclosing it publicly, avoid accessing or modifying data that is not your own, avoid degrading the Services or the experience of other users, and stay within the bounds of Applicable Law and the Acceptable Use Policy. Testing that involves denial-of-service, spam, social engineering of our personnel or customers, or physical intrusion is not authorized. When researchers report in good faith and follow these guidelines, we will not pursue action against them for the research itself, and we will treat their reports as a valued contribution to the security of the Services.

Shared Responsibility

Security of the Services is a partnership. eFind is responsible for securing the platform, the infrastructure it runs on, and the measures described in this document. Customers are responsible for how they use the Services and for the parts of the environment under their control. Neither party can deliver security alone, and gaps most often appear at the boundary between the two. The table below summarizes the division; the detail follows.

AreaeFind is responsible forThe customer is responsible for
Platform and infrastructureSecuring the Services, hosting infrastructure, and the controls in this PolicyUsing the Services in line with the Agreements and Policies
Account accessProviding authentication and multi-factor optionsProtecting credentials and enabling multi-factor authentication
ConfigurationOffering secure defaults and access controlsConfiguring settings, roles, and permissions appropriately
Integrations and API keysSecuring the APIs and issuing keysSafeguarding API keys and securing integrations
Customer content and systemsProtecting data within the ServicesSecuring Advertiser and Publisher systems, Landing Pages, and properties

Protecting Credentials

You are responsible for keeping the credentials that access your Account confidential, for choosing strong and unique passwords, for enabling multi-factor authentication where it is offered, and for making sure that only trusted Authorized Users can reach your Account. Many of the most damaging incidents affecting online services begin with a credential that was reused, shared, or left unprotected. Treat your credentials as keys to your data.

Configuring Your Own Systems

You are responsible for configuring the settings, roles, and permissions available in the Services in a way that fits your security needs, and for keeping the Devices and systems you use to access the Services patched and protected. We provide controls and sensible defaults; you decide how to apply them to your organization.

Securing Advertiser and Publisher Integrations and API Keys

If you connect to the Services through an API, integrate a Publisher Property, deploy Conversion Tracking, or otherwise build on top of the platform, you are responsible for securing those integrations. This includes protecting API keys and other secrets, storing them securely rather than embedding them where they can be discovered, rotating them when they may have been exposed, restricting their scope, and monitoring their use. An exposed API key can let someone act as you, so treat keys with the same care as passwords.

Reporting Concerns

If you believe your Account has been compromised, or you notice activity that concerns you, tell us promptly at support@efind.com or 1-214-444-8126 so that we can help you respond. Quick reporting is one of the most valuable things a customer can do, because it lets us contain problems before they spread.

How This Policy Is Reviewed and Updated

eFind reviews this Security Policy and the program behind it on a regular basis, and additionally when there is a significant change in our Services, our infrastructure, the threat landscape, or Applicable Law. Reviews are how we keep the words on this page aligned with the controls we actually operate. When we make material changes, we will post the updated policy on this page, and we will communicate significant changes through the means described in our Agreements and Policies. Because security is a continuous practice, we expect this document to change over time, and each version supersedes the ones before it.

Related Documents

  • Master Definitions
  • Governance
  • Privacy Policy
  • Data Processing Addendum
  • Acceptable Use Policy

Building Technology People Can Trust.

© 2026 eFind. All rights reserved.

eFind

About Contact Careers Mission Technology Trademarks

Advertising

eFind Ads eFind TV Earn with Ads Affiliates Countries Resources FAQ

Data

GDPR Policies Privacy Terms Equal Opportunity

Products

Search AI Search Mail Maps eTube News Weather
eFind
About Contact Careers Mission Technology Trademarks
Advertising
eFind Ads eFind TV Earn with Ads Affiliates Countries Support
Data
GDPR Policies Privacy Terms
Products
Search AI Search Mail Maps eTube News Weather
© 2026 eFind. All rights reserved. Made in the USA.