Security
Security practices.
Jarvan is built around least-privilege access, encrypted Google Ads tokens, and explicit campaign approval controls.
Google Ads access
Jarvan stores the selected advertiser customer ID and an encrypted Google refresh token. Campaigns are created only on the advertiser account selected by the user.
Automation controls
Campaign monitoring can propose actions for manual review or apply eligible changes automatically when auto-apply is enabled on that campaign.
Infrastructure
Authentication and database storage are handled through Supabase. Billing is handled through Stripe. AI inference is routed through OpenAI for campaign planning and chat workflows.
Reporting
Security issues should be reported to [email protected] with reproducible steps and impact. Jarvan does not offer a public bug bounty program at this stage.