Credential isolation
Application secrets and tokens are stored outside the public website and are not embedded in browser-delivered code.
Security
Application secrets and tokens are stored outside the public website and are not embedded in browser-delivered code.
Only permissions needed for authorized advertising operations are requested and used.
Sources, evaluations, recommendations, approvals, and outcomes are recorded for review.
Configured limits prevent exceptional actions from proceeding without human review.
Operational records follow defined retention periods and deletion procedures.
Read-only collection and evaluation can be verified before advertising changes are enabled.
Authorization boundary
The MVP callback listens only on the local loopback interface. It validates a short-lived, single-use state value before exchanging the authorization code.
The operator initiates authorization from the local application.
The platform presents and records the permissions being granted.
The local callback validates state and consumes the authorization code once.
Credentials remain in Windows-protected local storage and are redacted from logs.
Report a security concern
Email security@arkcentury.top with the affected URL, observed behavior, and safe reproduction steps. Never include passwords, tokens, or personal identity documents.