Skip to content

Trust centre

Security practices

Controls used to protect advertising authorizations, account information and the people who operate the service.

Access control

The operations application is not open registration. Access is limited to approved operators, protected by authenticated sessions, rate limits and optional multi-factor authentication. Administrative routes are separated from public business information.

OAuth and credentials

Advertising accounts are connected using platform OAuth. Users never enter their TikTok password into AC2 Business Hub. Application secrets and access tokens are kept server-side, encrypted at rest and excluded from browser responses and routine logs.

Minimum permission model

The submitted TikTok release requests only the account provisioning, campaign, creative and reporting permissions documented on our integration page. Additional data categories require a working product function, an updated public notice and any platform review required for expanded access.

Connection integrity

OAuth callbacks use a time-limited, single-use state value to bind the response to the connection that initiated it. Transport encryption is required for public and callback endpoints.

Monitoring and response

We maintain operational records needed to investigate failed authorizations and suspected unauthorized access. Confirmed incidents are contained, assessed and communicated in accordance with applicable legal obligations.

Report a concern

Send security concerns to [email protected]. Do not include passwords, access tokens or customer payment information.