Access control
The operations application is not open registration. Access is limited to approved operators, protected by authenticated sessions, rate limits and optional multi-factor authentication. Administrative routes are separated from public business information.
OAuth and credentials
Advertising accounts are connected using platform OAuth. Users never enter their TikTok password into AC2 Business Hub. Application secrets and access tokens are kept server-side, encrypted at rest and excluded from browser responses and routine logs.
Minimum permission model
The submitted TikTok release requests only the account provisioning, campaign, creative and reporting permissions documented on our integration page. Additional data categories require a working product function, an updated public notice and any platform review required for expanded access.
Connection integrity
OAuth callbacks use a time-limited, single-use state value to bind the response to the connection that initiated it. Transport encryption is required for public and callback endpoints.
Monitoring and response
We maintain operational records needed to investigate failed authorizations and suspected unauthorized access. Confirmed incidents are contained, assessed and communicated in accordance with applicable legal obligations.
Report a concern
Send security concerns to [email protected]. Do not include passwords, access tokens or customer payment information.