Security, privacy and governance安全、隐私与治理

Your account stays yours.你的账户始终是你的。

Handing advertising operations to a platform should not mean handing over control of the account. Access is granted by you, scoped to what you granted, revocable by you, and every change is on the record.把广告运营交给一个平台,不应该等于交出账户的控制权。访问权限由你授予、范围以你授予为准、可由你撤销,并且每一次变更都有记录。

Controls控制项

How access, credentials and change history are handled访问、凭证与变更历史如何处理

Encryption in transit

Everything moves over TLS, this website included. You can verify the transport for oduse.site yourself right now.所有传输走 TLS,本网站也不例外。oduse.site 的传输层你现在就可以自行验证。

Environment separation

Development and production are separate environments. A change under test cannot reach a live advertising account.开发与生产是分离的环境。测试中的变更无法触及在投广告账户。

Audit logging

Append-only records of who proposed a change, who decided it, the values before and after, the guardrail result and the timestamp.仅追加的记录:谁提出变更、谁做出决定、变更前后的值、护栏结果与时间戳。

Least-privilege access

Access is granted per role and per advertiser. There is no shared administrative account, and no standing access beyond what a task requires.按角色、按广告主授予权限。没有共享管理账号,也不保留超出任务所需的常驻权限。

Advertiser authorization and revocation

Access to an advertising account requires that advertiser's explicit grant, is scoped to what they authorized, and is revocable by them at any time. Revocation takes effect immediately for any new operation.访问广告账户需要该广告主的明确授予,范围以其授权为准,并可由其随时撤销。撤销对任何新操作立即生效。

Credential handling

Credentials and tokens are never exposed to the browser, never written to application logs, and never shared between advertisers.凭证与令牌绝不暴露给浏览器、绝不写入应用日志、绝不在广告主之间共用。

Incident response

A defined owner, a defined escalation path, and notification to affected advertisers. We do not publish a response-time SLA, and we would rather not invent one.明确的责任人、明确的升级路径、并通知受影响的广告主。我们不公布响应时间 SLA,也不打算凭空编一个。

Data retention and deletion

Advertiser data is retained while authorization is in force plus a defined window, and is deleted on request.广告主数据在授权有效期加一段明确的窗口内保留,并可依请求删除。

Third-party dependency review

The external dependency surface is kept deliberately small and each dependency is reviewed before it is introduced. This website loads no third-party code at all.外部依赖面被刻意保持很小,每个依赖引入前都经过评估。本网站完全不加载任何第三方代码。

Reporting a security issue报告安全问题

If you believe you have found a security problem with this website or with anything we operate, email contact@oduse.site with enough detail to reproduce it. We will acknowledge it. We do not currently run a paid bug bounty, and we will not pretend otherwise.如果你认为在本网站或我们运营的任何系统中发现了安全问题,请发邮件到 contact@oduse.site,并附上足以复现的细节。我们会予以回复。我们目前没有付费漏洞赏金计划,也不会假装有。