What DecryptAds Does
Picture an avalanche relentlessly slamming into a mountain’s worth of old mine shafts for years on end until exploring them is more extraction than navigation, and you’ll have a sense of just how murky and muddied the programmatic advertising ecosystem has become. Even for researchers, trying to pull data from the noise of what is happening on publishers’ websites and apps is difficult on the best of days, if not nigh-impossible.
Knowing which data brokers are collecting data from which sites, which foreign companies are involved in which advertising supply chains, or even knowing what questions to ask in the first place? A convoluted nightmare that only gets more complex with each passing minute.
Until now, that is.
Introducing DecryptAds, a peerless analytics platform for the programmatic advertising supply chain. Built out of a burning desire to solve unanswered challenges and confounding questions alike in this space, DecryptAds was designed first and foremost by public researchers, to serve both researchers and the public.
DecryptAds acts as the world’s first looking glass and lodestone for this space, clearing away the dirt, grime, and mud left by legions of ever-shifting advertising files, sites, and supply-chains to hand its users a detailed map of where they want to go. Only this living data map embeds more layers of context, reference points, historical data, and demonstrably source-verifiable insights than any hand-drawn map or printed series of spreadsheets ever could.
Our platform is the investigative command center from which you can launch a hundred investigations at once, and finish them all before the week is out (or have your favorite agent[s] assist via our fully fleshed out MCP server!)
What DecryptAds Sees
Supply-chain integrity issues rarely live in a single file. They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files; as cloned declaration sets across unrelated domains; as seller removals that only make sense when viewed across exchanges; and even as supply paths in bid logs that never actually appear in any given publisher’s authorized-seller list.
DecryptAds crawls and parses the IAB transparency stack (alongside other data points) and merges it all into a comprehensive, clear, and queryable corpus of easily accessible data. Then it runs a slew of analytical engines across the entire thing to compress what would otherwise be hours or weeks’ worth of tab-by-tab comparison into exportable evidence broken down by evidence-based weights and scores.
Our platform doesn’t replace human judgment (what could?), but it does cleanly render, simplify, and resolve a number of the industry’s largest headaches into easily digestible (and sourceable + shareable) formats.
You’ll find a sneak-preview of some of those formats, and a few of the analytical tools we’re ready to share publicly (and available in the product) below:
What You Can Do With DecryptAds!
Auto-Investigate
Problem: A suspicious hostname comes across your desk and triggers dozens of questions: Is its sellers.json consistent with its ads.txt? Did its “OWNERDOMAIN” field change? Are its partners operating in or from flagged jurisdictions? Is the site Made-For-Advertising (MFA) or is it MFA-like? The manual review ahead of you scatters these answers and more across heaps of files, crawl logs, and registries. Answering these questions manually will require coffee in copious amounts for your team, in volumes that make delivery by barrel the most expedient.
Solution: Enter any hostname into DecryptAds and it’ll run roughly 35 checks across 11 different categories, performing a variety of cross-reference validation checks, temporal diffs, crawl integrity confirmations, TAG-ID checks, MFA lab signals, data broker registry checks (CPPA, Vermont, and Texas for now), jurisdiction screening on their partners, and more.
All findings get rolled into a channel-based risk score from 0 to 100, with individually scored items you can single out for export as case files, served up hot before the coffee is.
Try it:
Tools → Auto-Investigate
(decryptads.com/investigate)
· API: GET /api/analytics/investigate/{hostname}
Publisher profile
Problem: Now that you’re armed with a measure of how suspect the subject of your investigation is, it’s time to go deeper. To dive into the full hostname dossier: OWNERDOMAIN / MANAGERDOMAIN, crawl freshness, Tranco rank, mislabel rates, constellation peers, geo-risk chips, and which registry-listed vendors sit in ads.txt. It’s a bog-filled quagmire on your desk, but once again, this is one DecryptAds was built to solve.
Solution: Simply search via the Publisher dropdown at the top (or click on “View full hostname profile” from your Auto-Investigate results) to open the publisher page. The badges here summarize crawl status, MFA/geo/registry signals, and declaration health for you, readily skimmable in a single glance. Deeper panels cover a given publisher’s data-broker registry presence (CPPA, Texas, Vermont), their vendor inventory from ads.txt / app-ads.txt / sellers.json, supply-chain shortcuts, and provide yet-more exportable reports. All the same evidence Auto-Investigate scored previously, laid out in one place for easy due diligence.
Try it here: Header search → Publisher dropdown · From Auto-Investigate → View full hostname profile
Ad system profile
Problem: As every good researcher knows, the other half of every ads.txt edge is the exchange itself. Investigators need to be able to measure the ‘freshness’ of a sellers.json file, its footprint corpus (i.e. how many publishers authorize it), its contact + identifier disclosure, and an exchange-level risk score would be ideal for this… which is why DecryptAds provides one.
Solution: Search Advertising System for a domain such as
pubmatic.com. The ad-system profile page will then show various statistics about its
sellers.json and buyers.json files, publisher count(s), contact and identifier cards, geo-risk status,
and an ad-system risk gauge. From there you can also jump over to hostname view or back to
Auto-Investigate for publishers that authorize this exchange; thus completing the site → partners →
exchange circuit in its entirety.
Try it here: Header search → Advertising System · Research → Ad Systems (decryptads.com/ad_systems)
Supply chain map & schain validation
Problem: Supply chains are the sources of truth holding key details that investigators need, and schain validation is easier to talk about than to do. Declarations show authorization edges across the chain, which can be painstaking to extract without missing something. Between that and the need to validate OpenRTB SupplyChain objects against everything they’re seeing, investigators have been faced with a multifaceted problem with no single way forward… until now, that is.
Solution: DecryptAds’ supply chain map builds a verified, source-backed graph built from a given publisher’s latest files (primarily ads.txt or app-ads.txt), cross-checks each edge against their sellers.json file, and then performs an additional follow-through hop from each intermediary in the chain’s own file(s). This provides a clear, comprehensive look at the entire supply chain, where each node can be easily clicked and expanded for further investigation.
DecryptAds’ Schain tools, on the other hand, validate serialized SupplyChain payloads and support path fingerprinting for repeated topology across impressions. Which is a fancy way to say they make your life easier by tracing the complex paths for you and surfacing the details you need to get the answers you and your organization are after.
Try it here: Tools → Supply chain map · Tools → Schain tools (decryptads.com/schain)
Declaration constellation fingerprints
Problem: You suspect you’ve come across a ‘clone operator’, i.e. an actor or group who copies entire ads.txt configurations onto new domains. Comparing publishers pairwise to prove this doesn’t scale, but the problem itself certainly does. More and more of these are crossing your desk each day. So, what can an ad researcher, site operator, auditor, or concerned member of the public do?
Solution: Why, turn to DecryptAds’ constellation fingerprints of course! Our platform normalizes every authorized-seller line from the latest available snapshot, providing its ad system, account ID, whether the relationship is “DIRECT” or “RESELLER”, and then fingerprints the full set for you as a ‘constellation [of sites]’ fingerprint. Sites sharing the same constellation fingerprint are exact ‘declaration clones’, and our similarity index even surfaces close matches. This saves yet-more time, identifying domains that share most of the same partners but not all of them, without requiring you to compare every pair across even our accessible (and hefty) database.
Try it here: Research → Declaration fingerprints (decryptads.com/declaration_constellation)
Ad Systems & Geo Risk
Problem: Investigating exposure to sanctions, navigating financial secrecy jurisdictions, and surfacing potential adversarial country registration conflicts before these things become a legal headache (or fine!) is a serious matter. These details often appear in sellers.json files’ contact addresses, though not always as desired. A given publisher’s partner list can thus potentially carry additional geographic risk an organization might miss if they were only reading declarations.
The same concern goes double for privacy: transparency files show which ad systems a given site authorizes, whereas live ad tags and bid requests can pass user and device metadata through to those partners. A news site read by government officials for example, or any publisher handling/serving sensitive audiences, may be routing signals to exchanges whose registered contact details place them in jurisdictions you or your organization may deliberately choose not to use. For example, jurisdictions designated as “countries of concern” under Executive Order 14117 of U.S. policy (codified by the Department of Justice in 28 C.F.R. Part 202 as China, Russia, Iran, North Korea, Cuba, and Venezuela). Properly assessing geographic risk in the programmatic ad ecosystem means not only considering potential supply chain abuse; but also mapping where a visitor’s data and metadata can flow once those relationships exist.
Solution: DecryptAds resolves this by providing keyword-based country inference on contact text which is then tiered against OFAC sanctions, EO 14117 countries of concern, FATF/TJN financial-secrecy lists, and other elevated-risk jurisdictions to surface potential concerns our users may be investigating. Our ad system directory ranks exchanges by their footprint across our entire data corpus and the Jurisdiction flags view shows groups of flagged systems across multiple tiers. DecryptAds also builds hostname profiles, which can surface the same signals from a given publisher’s declared partners.
Disclaimer: A match here means a jurisdiction string appeared in a self-reported address field. It does not, by itself, conclusively establish where a company operates, who controls it, where data is processed or stored, or that any legal restriction applies. It is an indicator of where to investigate next (corporate registries, filings, hosting, DNS evidence, direct inquiry, etc).
Try it here: Research → Ad Systems · Research → Geo Risk (decryptads.com/geo_risk)
Quiet Removals Feed
Problem: When a seller quietly disappears from an exchange’s sellers.json file, that is often a slow-burn risk signal that researchers key in on. One that other advertisers would love to have to inform their own decision making… but it only captures a piece of the problem, and even worse: it doesn’t scale. It can also miss even more important context, such as coordinated scrubbing events occurring across multiple ad systems.
Solution: DecryptAds solves this by tracking seller removal transitions between crawled snapshots and clustering removals that hit multiple exchanges via our Quiet Removals Feed. It’s even got its own page and dashboard, which highlights recently removed sellers, supports historical / timeline reviews, and offers an easy export option for bulk inspection.
Try it here: Research → Quiet Removals Feed (decryptads.com/quiet_removals_feed)
Network clusters
Problem: Often researchers will come across operators who are rotating their domains while reusing the same monetization infrastructure over and over. Examining these identical “DIRECT” account sets or full copied declaration files can reveal what’s going on, but doing so one at a time guarantees your day will be filled with a flood of browser tabs and quiet exasperation.
Solution: DecryptAds resolves both of these cluster types at scale, with powerful visual maps that break down each cluster in detail. Specifically, these show sites that share the same set of DIRECT exchange-and-account combinations and sites whose ads.txt or app-ads.txt declarations fingerprint identically. Both rely on precomputed fingerprints rather than comparing every site pair by hand, greatly speeding up the analytical process.
Try it here: Research → Network clusters (decryptads.com/network_clusters)
Impression log analyzer
Problem: Bid and impression logs describe what actually ran in the market, but declarations describe what should be authorized and it is that very “should be” which is often the subject of investigation. Bridging these two is a manual, format-dependent process that takes far longer than it should.
Solution: Simply upload an OpenRTB JSONL, or vendor exports (GAM, Xandr, TTD REDS, APS — CSV, TSV, or Parquet where supported) on DecryptAds’ “Impression Log Analyzer” page to pierce the proverbial veil. Our platform’s analyzer auto-detects the requisite format(s), ranks publishers alongside exchange-and-account pairs, validates supply-chain metadata in bid requests when/where present, and can join traffic to your crawled transparency files in order to flag paths that do not match their declarations. Advanced options exist and are provided in readily accessible inputs and dropdowns.
Try it here: Research → Log analyzer (decryptads.com/impressionlogs)
At this point, the logical next question is how to automate these tools, and does DecryptAds have APIs available? To which the answer is an unequivocal: absolutely!
Everything you can do on our platform can be automated via DecryptAds’ comprehensive APIs, and as an AI-Native platform our MCP server allows you to task agents to do the same!
To get started, refer to our How to use the API and Using DecryptAds with MCP pages.
If you’re every bit as excited as we are about all of these new capabilities in the programmatic ad ecosystem, happen to work in the ad-tech space, and/or want hands-on access for a specific use case then hop on over to request a beta invite (decryptads.com/beta-invite) and we’ll see you soon!