Legal

Security Policy

Last Updated: April 12, 2026

At Factor42, security is foundational to how we operate. We handle sensitive campaign data, advertising account credentials, and performance metrics on behalf of hundreds of media companies and agencies. This Security Policy describes the technical and organizational measures we maintain to protect that information.

GDPR Compliant CCPA Compliant SOC 2 Type II (In Progress)

1. Security Program Overview

Factor42 maintains a formal information security program aligned with industry best practices, including the NIST Cybersecurity Framework and ISO/IEC 27001 principles. Key elements of our program include:

2. Data Encryption

2.1 Data in Transit

All data transmitted between clients, our systems, and third-party platforms is encrypted using TLS 1.2 or higher. We enforce HTTPS across all Factor42 web properties and reject connections using deprecated protocols (TLS 1.0, TLS 1.1, SSL).

2.2 Data at Rest

All client data stored within Factor42 systems is encrypted at rest using AES-256 encryption. Encryption keys are managed using a dedicated key management service with strict access controls and rotation policies.

3. Access Controls

3.1 Role-Based Access

Access to client data and internal systems is governed by a strict role-based access control (RBAC) model. Employees are granted access only to the systems and data required for their specific job functions (principle of least privilege).

3.2 Multi-Factor Authentication

Multi-factor authentication (MFA) is mandatory for all Factor42 employees accessing internal systems, client advertising accounts, and cloud infrastructure. Single-factor authentication is not permitted for any privileged access.

3.3 Access Reviews

Access rights are reviewed on a quarterly basis. Terminated employee access is revoked within one (1) business day of offboarding.

3.4 Client Account Access

Factor42 accesses client advertising platform accounts (e.g., Google Ads, Meta Business Manager) strictly through official platform APIs or delegated access mechanisms. We never request or store client platform master passwords. Access is limited to personnel directly assigned to the client account.

4. Network Security

5. Vulnerability Management

6. Incident Response

Factor42 maintains a formal Incident Response Plan (IRP) covering detection, containment, eradication, recovery, and post-incident review. Key commitments:

7. Employee Security

8. Third-Party Vendor Security

Factor42 requires all third-party service providers who access or process client data to meet our security standards:

9. Data Handling and Segregation

10. Physical Security

Factor42 operates on cloud infrastructure hosted by SOC 2 Type II and ISO 27001-certified cloud providers. Physical security of data center facilities — including access controls, surveillance, and environmental controls — is maintained by our cloud infrastructure partners in accordance with their respective security certifications.

11. Compliance and Certifications

12. Responsible Disclosure

If you believe you have discovered a security vulnerability in Factor42's systems or services, we encourage responsible disclosure. Please report your findings to security@factor42media.com with a detailed description of the vulnerability, steps to reproduce, and potential impact. We commit to:

We ask that you not publicly disclose the vulnerability until we have had a reasonable opportunity to investigate and remediate.

13. Contact

For security-related inquiries, incident reports, or responsible disclosure: