Current security posture
DreamHire is in a private pilot. The current product surface supports read-only Amazon Ads monitoring, shadow recommendations, and offline-safe simulations. Live advertising writes are disabled while the authorization, guardrail, and verification layers are completed and reviewed.
Core controls
Invite-only identity
There is no open self-registration path. Access depends on a valid activation invitation and organization membership.
Strong operator authentication
The production design uses verified email sessions and requires TOTP two-factor authentication for privileged roles.
Private service network
Application databases, workflow services, and workers have no public listener. Private object-storage buckets require scoped service credentials even though their provider endpoint is internet-reachable.
Encrypted credentials
Amazon refresh credentials are stored as versioned authenticated ciphertext. Public responses and origin access logs do not return token material.
Separated authority
Reasoning, policy, workflow, and Amazon access run across explicit boundaries. The AI layer cannot contact Amazon directly.
Durable audit evidence
Recommendations, policy decisions, approvals, execution attempts, and verification results are represented as distinct records.
What we do not claim
DreamHire does not currently claim a third-party security certification. This page describes architectural intent and implemented pilot boundaries, not an independent audit or a guarantee that incidents cannot occur.
Reporting a security concern
Email the official submission route at [email protected] with the subject Security report: DreamHire. Report suspected credential exposure, unauthorized access, cross-customer data, or unexpected Amazon activity immediately. Do not exploit a concern further, access another customer’s information, or disrupt the service to prove impact.
Safe information to include
- Your name and a safe way to contact you.
- A concise description of the concern and its potential impact.
- The affected DreamHire URL or component and the approximate UTC date and time.
- Reproduction steps that do not access another customer's data or disrupt service.
- Safe request, case, or organization identifiers that do not reveal credentials or Amazon Ads content.
Do not send secrets or customer data
Email is not an approved evidence-transfer channel. Never include any of the following in the initial report:
- passwords or recovery codes
- Amazon access or refresh tokens, OAuth codes, or Login with Amazon client secrets
- encryption keys, signed URLs, session cookies, or database credentials
- raw Amazon Ads reports, customer search terms, or another customer's data
Refer to sensitive material by a safe identifier. If evidence is required, DreamHire will arrange a restricted transfer path after triage.
How reports are handled
- Submit and retain a receipt. Email is the official submission route, but it is not a synchronous emergency service. Keep the sent message and delivery receipt. If delivery fails, use your established DreamHire support contact without including secrets or customer data.
- Acknowledge, track, and triage. After receipt, DreamHire opens a restricted internal case, returns a safe reference when it is appropriate to do so, and assesses severity, affected systems, customer scope, and whether credentials or Amazon information may be involved. Active exposure, unauthorized access, or unexpected Amazon activity bypasses routine handling for containment.
- Investigate and update. We preserve evidence, investigate through restricted systems, and provide updates at material changes or an agreed checkpoint. We may withhold details that would expose customers, evidence, or defensive controls.
- Resolve and close. Resolution time depends on scope, so we do not promise an artificial closure date. We validate containment and remediation, record the outcome and follow-up work, and notify the reporter when the case is closed when it is safe and appropriate to do so. A closed report can be reopened if material new evidence appears.
A report that actually or potentially involves Amazon Ads credentials, Amazon Ads information or derivatives, cross-customer exposure, or an unauthorized Amazon action is escalated under DreamHire’s Amazon-data incident process. DreamHire contains the affected path, preserves evidence, and notifies Amazon and affected customers when required by the applicable agreement, law, and incident scope. Investigation details are shared only on a need-to-know basis.
