Security
TapMind trust and compliance information for publishers' procurement and security teams.
Security at TapMind
Where data lives. TapMind's platform runs on major cloud infrastructure providers, primarily in India, with backups kept in the same region as the data they copy. Current providers and locations: Sub-processors.
How identifiers are protected. Advertising identifiers are held only in memory on the device, sent over TLS 1.2+, and stored encrypted at the field level under managed keys with no routine human access. Serving logs are keyed on a pseudonym that cannot be linked back once a user's data is deleted.
What we don't collect. No precise location, no hardware identifiers, no device fingerprints, no contact details. Every SDK release publishes a machine-generated list of what it collects.
Access and audit. Role-based access; every privileged action (enabling a feature, changing a policy, deleting data) is logged with who, when and why, and retained seven years.
Retention. Automated deletion on the schedules in our Privacy Policy, verified weekly.
Incidents. A documented response plan with defined notification paths to publishers and regulators; annual exercise.
Found a vulnerability? See Report a Vulnerability.
Certifications. TapMind does not currently hold third-party security certifications. When a SOC 2 or ISO 27001 engagement is completed, it will be listed here with the date.
Questions. Security questionnaires: privacy@tapmind.com.