Transparency

Every node declared. Every partner registered. Every claim verifiable.

We wrote the exchange ourselves: the wire contract, the auction, the anti-fraud checks, the logging layer. So transparency here is not a promise about a black box, it is the same set of artifacts we operate on, published for anyone integrating with us.

Public files

Three files. Canonical location. No redirects.

The obligation runs both ways. A scheduled robot rechecks the ads.txt and app-ads.txt of every connected property, matches the declarations against the domains and app bundles that actually reach our endpoints, and writes the result into the publisher console. A declaration that does not resolve is a supply path we do not open.

Standards we comply with

Protocol, supply chain, privacy. Each one checkable against our traffic.

  • OpenRTB 2.5 / 2.6Wire contract in both directions: inbound from supply partners, outbound to every DSP.Protocol
  • SupplyChain Object 1.0source.ext.schain populated on every bid request we surface, with hp=1 on the Adbustr node.Supply chain
  • sellers.jsonPublished at the canonical location, no redirects, seller_type and is_confidential declared per entity.Supply chain
  • app-ads.txt / ads.txtPublished at the canonical locations, and rechecked on connected properties by a scheduled robot with the status shown in the console.Supply chain
  • VAST 2, 3, 4Video responses served as InLine or Wrapper. VPAID is accepted from resale partners as pass-through media; we operate no VPAID renderer.Protocol
  • Header biddingPrebid adapter and server-to-server feeds, on the same canonical request as every other entry point.Protocol
  • IAB Tech Lab content taxonomysite.cat and site.sectioncat enforced inbound; IAB25, IAB25-3 and IAB26 blocked on mainstream endpoints.Protocol
  • imp.secureSecure flag propagated end to end: HTTPS inventory receives HTTPS creative.Protocol
  • GDPRDPA available on request. Serving and data infrastructure run inside an isolated private-network perimeter.Privacy
  • CCPAOpt-out signals propagated to every downstream demand partner.Privacy
  • TCF v2.2IAB Europe consent framework: consent string parsed inbound and forwarded outbound.Privacy

How we treat traffic quality

Nine checks at the door, a reason code on every rejection.

Filtering happens before the auction, not after the invoice. Every request that reaches a downstream DSP has passed our inbound contract checks and the nine realtime anti-fraud checks, and every request that did not is still logged, with the reason it was stopped. The policy below states each control by name.

Nine anti-fraud checks per request

Nine realtime checks run on every inbound request, among them bot user agents, datacenter IP and ASN ranges, geo mismatch, duplicate requests, rate limits, Tor exits and managed lists. Each endpoint runs them in shadow or in block mode, so a partner can see exactly what would be cut before anything is cut.

Inbound contract checks and routing, Resonance

Before any of that costs compute: device.ip and device.ua are mandatory, the user agent must resolve to our browser allow-list, and adult and illegal content categories (IAB25, IAB25-3, IAB26) are rejected on mainstream endpoints. Advertiser-domain blocklists (badv) are applied at the publisher level. What survives is enriched (GeoIP, browser and device classification) and routed to eligible demand.

Source scoring and independent verification

Supply sources are re-scored hourly on a 0 to 100 scale, with quarantine before a ban, and the score is visible in the console rather than applied silently. Our impression and click pixels, win notices and per-request logs are structured for reconciliation by third-party verification partners engaged by our counterparties, and findings raised against our supply trigger a root-cause review.

Per-request audit trail

Every request gets a verdict. Every no-bid gets a reason.

Each inbound OpenRTB request is written to a per-request funnel table in ClickHouse: request id, endpoint, publisher, format, geo, domain, selected demand feed, verdict (bid or no-bid), the reason code behind it, the winning price and the revenue share applied. Impression and click pixels, plus nurl, burl and lurl notices, land in the same store. When a partner asks why their traffic did not monetise, the answer is a query, not an opinion.

  • unknown_endpointEndpoint uid is unknown or disabled.
  • no_ip_uadevice.ip or device.ua missing from the request.
  • browser_not_allowedUser agent does not resolve to an allowed browser.
  • non_mainstreamIAB25 / IAB25-3 / IAB26 category on a mainstream endpoint.
  • fanout_offDemand fan-out is toggled off: request accepted and logged, no DSP spend.
  • no_impEmpty imp array.
  • no_feedsNo live demand feed configured for the endpoint.
  • HTTP 400Body does not parse as JSON.
  • HTTP 204No-bid returned for any of the reasons above.

Reporting

Log level for the partners who need it. Dashboards for everyone else.

Reporting API

Authenticated per-partner API over the same aggregates our own dashboards read: impressions, spend, revenue share and fill, broken down by publisher, zone, DSP, format, country and day.

Self-serve dashboards

Publisher and advertiser cabinets expose the numbers behind the invoice, sourced from the aggregation layer rather than a separately maintained marketing view.

Statement reconciliation

Our counts are reconciled against DSP-side statistics, and Adbustr publishes the delta rather than absorbing it silently. Discrepancies are worked as engineering tickets against the raw logs.

Audit access

Active DSP partners may request log-level data access for reconciliation purposes under our standard audit protocol. Brand advertisers may request inventory breakdowns specific to their campaigns. Serving and data infrastructure run on dedicated servers inside an isolated private network; operator access goes through our own VPN, and a Data Processing Agreement covering GDPR and CCPA obligations is available on request.

ask@adbustr.com

See it on your own traffic

The fastest audit is your own console.

Every artifact on this page has a counterpart inside the console: the reason code behind each no-bid, the ads.txt verification status of each property, the cleared price behind each impression and the revenue share applied to it. Open an account and read them against your own requests.

Sign-up is three screens: email, password, code. The console opens immediately; traffic starts after review.