Security is a core part of how we build and operate AdChat. This page describes the measures we take to protect your data and the steps we follow when something goes wrong.
Encryption
All data transmitted between your browser (or connected channels) and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and reject plaintext HTTP connections.
Sensitive credentials stored in the database — such as bot tokens and access tokens for connected channels — are encrypted at rest using AES-256-GCM with a server-side encryption key stored separately from the database. User passwords are hashed with scrypt and are never stored in plaintext.
Access controls
Access to production infrastructure is restricted to authorized personnel only, using SSH keys and multi-factor authentication. We follow a principle of least privilege: each service and team member is granted only the permissions necessary to perform their function.
Within the application, all queries are scoped to the authenticated workspace. No user can access data belonging to another workspace. Role-based access control (admin, member) governs what actions users can perform within their workspace.
Monitoring
We monitor our infrastructure and application for anomalous activity, errors, and performance degradation. Logs are retained for a limited period and are used to investigate incidents. Sensitive values such as credentials and tokens are redacted from all logs.
Webhook processing includes signature verification to ensure that only legitimate payloads from Telegram and Meta are acted upon.
Incident response
In the event of a security incident that may affect your data, we will notify affected users by email within 72 hours of becoming aware of the incident, as required under applicable data protection regulations. Notifications will describe the nature of the incident, the data involved, and the steps we have taken or are taking to address it.
We maintain an internal incident response runbook that is reviewed and updated periodically.
Third-party audits
We have not yet commissioned an independent third-party security audit or penetration test of the AdChat platform. We intend to engage an external security firm as the product matures. This page will be updated when audits are completed.
We host the Service on infrastructure we operate ourselves, with Cloudflare in front of the public edge. The database and cache are self-managed rather than managed services, so no third-party certification covers them.
Bug bounty
We welcome responsible disclosure of security vulnerabilities. If you discover a potential security issue in AdChat, please report it to us through the contact form before publicly disclosing it.
Please include a description of the vulnerability, steps to reproduce it, and its potential impact. We will acknowledge your report within 48 hours, keep you informed of our investigation, and aim to resolve confirmed issues promptly. We do not currently offer monetary rewards, but we will credit researchers in our changelog when a fix ships (with your permission).
We ask that you do not access, modify, or delete user data; disrupt production services; or conduct social engineering attacks as part of your research.
Operator
- Company
- «ADCHAT» LLC
- Address
- Fergana, Republic of Uzbekistan
- legal@adchat.uz
- Website
- adchat.uz