1. What Kvant Media is

Kvant Media is a service brand, not a claim that a registered company or TikTok representative exists. The technology work focuses on reporting, measurement, and human-reviewed decisions for authorised advertising accounts.

2. Website controls

  • Production traffic is intended to use HTTPS with HSTS at the edge.
  • Content Security Policy blocks objects, frames, cross-origin forms, and inline event-handler attributes.
  • Responses include anti-sniffing, clickjacking, referrer, permissions, cross-origin, and legacy cross-domain policy headers.
  • This public marketing site has no client dashboard and does not expose TikTok access tokens in browser code.

3. API data boundary

When an account owner authorises the optional TikTok workflow, the current scope is read-only reporting: account information and consolidated performance reports. The workflow does not request campaign write permissions and does not create, edit, pause, or delete campaigns. If API access is unavailable, an authorised Ads Manager export can be used instead.

  • Credentials stay in the restricted operator environment, never in this public site or client-side JavaScript.
  • Only the advertiser accounts and reporting period explicitly supplied by the account owner are processed.
  • Public pages contain no client account metrics, access tokens, or private dashboard data.

4. Operational requirements

A future client dashboard must be protected with an identity layer such as Cloudflare Access before real client data is published. A direct static-host URL must not bypass that protection. Tokens should be stored in a secret store, limited to the smallest required permissions, rotated when staff or client access changes, and revoked by the account owner when the engagement ends.

These controls are engineering practices, not an ISO 27001, SOC 2, or other compliance certification. We do not claim a certification that has not been independently obtained.

5. Responsible disclosure

Report a suspected vulnerability to contact@kvant-media.com with the affected URL, steps to reproduce, approximate time, and a safe proof of impact. Please do not access another person’s account, download private data, or run disruptive tests. We will acknowledge a useful report and coordinate a fix or mitigation.

See the machine-readable policy at /.well-known/security.txt, the API workflow description, and our Privacy and Terms.