Security
Security and access controls
Riptide separates customer accounts, limits access to credentials, and applies privacy signals before using identifiers or targeting audiences. Permissions and audit logs help you control human and agent access.
Account isolation
Database access rules separate each customer's inventory, campaigns, and reporting. Cross-account operator access must be explicitly authorized and is audited.
Credentials and signing keys
Riptide loads credentials from runtime configuration or a managed secret store. Tenant signing keys are encrypted and support rotation. Tracking links use sealed identifiers.
Privacy signals
Consent, Do Not Track, and jurisdiction signals determine whether Riptide can use identifiers, sync users, or contact demand partners. These checks apply before the request leaves the platform.
Request validation
Riptide checks incoming ad requests, tracking events, and API calls for valid content and size limits. Invalid ad requests can return a no-bid or empty response so the player can continue.
Agent permissions and audit
Each agent has an identity, permissions, and limits on the actions it can take. You can require approval for selected changes. Approval does not override permissions or spending caps. Audit records capture the actor, reason, and changes for review.
Your responsibilities
Choose account roles and agent permissions for the work each person or agent needs to do. Keep credentials secure and forward the consent signals collected by your integration.
Reporting a concern
If you believe you have found a security issue in Riptide, please email [email protected] with reproduction steps. We ask that you give us a reasonable window to investigate and address a report before any public disclosure.
Review your access requirements
Tell us who needs access, how you separate customer accounts, and which identity provider you use. We can work through the roles and sign-in setup with your team.