How it is built
Security
Last updated 25 September 2026
Your data is separated by what you own, not by a filter
Every organisation is assigned a set of advertiser accounts. That assignment is the isolation boundary: the service resolves it from the database on every single request rather than trusting anything in your session token, so removing a brand takes effect on the next page load rather than when a token expires.
A competitor's numbers are never in your account
You can see who else advertises in your category and how often — that is observable by anyone looking at ChatGPT. You cannot see Advox's assessment of a named competitor, because that is our judgement about them and frequently work somebody else is paying for. Benchmarks are always pooled across a category with a sample size attached, never a table of rivals with rates beside their names.
Your browser never holds a credential
The portal is rendered on the server. Your session lives in an http-only cookie that page JavaScript cannot read, and the key that reaches our measurement API never leaves our servers. There are no third-party scripts on the signed-in product and no analytics tags anywhere on this site.
Sign-in is by invitation
There is no open registration. Accounts are created from a code we issue to a named organisation, codes carry a use limit and can be withdrawn, and every redemption is recorded against the account that used it.
Reporting something
If you believe you have found a vulnerability, write to security@advox.ai. We will acknowledge within two working days and will not take action against anyone reporting in good faith.