Back to home

Security

Security practices.

Jarvan is built around least-privilege access, encrypted Google Ads tokens, and explicit campaign approval controls.

Google Ads access

Jarvan stores the selected advertiser customer ID and an encrypted Google refresh token. Campaigns are created only on the advertiser account selected by the user.

Automation controls

Campaign monitoring can propose actions for manual review or apply eligible changes automatically when auto-apply is enabled on that campaign.

Infrastructure

Authentication and database storage are handled through Supabase. Billing is handled through Stripe. AI inference is routed through OpenAI for campaign planning and chat workflows.

Reporting

Security issues should be reported to [email protected] with reproducible steps and impact. Jarvan does not offer a public bug bounty program at this stage.