Platform

What happens between a request and a record.

The mechanics behind AdStack: how delivery is divided, how events are verified, how IP data and fraud signals shape decisions, and how the output reaches your reporting.

01

Weighted delivery and allocation.

When several campaigns compete for the same placement, someone has to decide the split. AdStack does that with weights. Each eligible campaign carries a weight, and its share of delivery is its weight divided by the total of all eligible weights.

Eligibility comes first. A campaign that fails a geographic rule, a cap or a policy check is removed from the pool, and the remaining weights are recalculated over what is left. The split always adds up to the whole.

The result is controlled distribution you can predict in advance and check afterwards against the delivery tracker.

Worked example · illustrative weights

Campaign A
5 / 10
Campaign B
3 / 10
Campaign C
2 / 10

Campaign C fails a geography rule for this request, so it leaves the pool. The remaining weights are 5 and 3, a total of 8.

Campaign A
62.5%
Campaign B
37.5%
share(i) = weight(i) / sum of eligible weights
02

HMAC-based event signing.

A tracking URL is just a URL. Anyone who learns the pattern can call it, which turns a counter into something that can be inflated at will. Signing closes that gap.

AdStack builds each tracking URL with a signature, an HMAC computed over the event parameters using a secret key held server-side. When an event arrives, the signature is recomputed from the parameters received and compared with the one supplied. A match is recorded. A mismatch is rejected and flagged.

Because a timestamp can be part of the signed values, stale URLs can also be treated differently from fresh ones. The secret never appears in the URL itself.

A shield with a check mark and a key above a data packet
03

MaxMind IP intelligence.

AdStack uses MaxMind data to detect and classify the IP address behind a request. That supports geographic and policy decisions made before an ad goes out: which regions a campaign may serve in, which it must skip, and which requests deserve a closer look.

It also feeds delivery controls. A country rule, for example, is applied to the IP at request time and recorded with the event, so the decision can be audited afterwards.

IP geolocation is a strong signal, not a certainty. Accuracy varies by region and by connection type, and VPNs or carrier networks can blur it. Rules should be written with that in mind.

  • IP detection. Recognise and classify the address on each request.
  • Geographic rules. Allow or restrict delivery by region.
  • Policy support. Apply your own conditions before a campaign is eligible.
  • Recorded outcome. Keep the decision attached to the event for audit.
04

Fraud-signal monitoring and decisioning.

AdStack watches for patterns that do not fit genuine viewing and passes what it finds to decisioning. These are signals, weighed together, and not a verdict from any single check.

A magnifying glass over a stream of packets with one flagged
  • Failed signaturesEvents whose HMAC does not match the parameters they carry.
  • RepetitionUnusual bursts of identical events from one address or range in a short window.
  • Geography mismatchAn event arriving from somewhere that does not fit the request that produced it.
  • Tracker disagreementCounts that diverge between delivery, impression and event trackers.
  • IP characteristicsAddress properties surfaced by IP intelligence that warrant a stricter rule.
AllowLimitFilterFlag for review

A realistic expectation. No system removes invalid traffic entirely. Thresholds and the response to each signal are agreed for each integration and revisited as traffic changes.

05

Multiple independent trackers.

One tracker gives you one opinion. AdStack runs separate trackers for separate questions, so a gap between them becomes information.

Four beacon nodes feeding one central ledger card
Delivery

Was it served?

Records that the ad file was delivered to the requesting device.

Impression

Did it start?

Records the impression when playback or rendering begins.

Event

What happened next?

Captures progress, completion and interaction events.

Quality

Does it hold up?

Monitors signature checks and anomalies across the other three.

Third-party trackers are supported alongside. Impression, click and event pixels, advertiser or agency VAST tracking URLs, viewability and verification tags, and mobile attribution postbacks can be carried with the ad and fired at the right moment. They run in addition to AdStack's signed trackers, which gives you two sets of numbers to compare.
06

Quartile tracking for video.

A video ad is measured while it plays. The player reports when the ad starts, when it passes 25%, 50% and 75% of its duration, and when it completes. These are the standard VAST progress events, and each one fires its own signed tracker.

  1. 0%start

    Playback of the ad begins.

  2. 25%firstQuartile

    A quarter of the ad has played.

  3. 50%midpoint

    Halfway through the ad.

  4. 75%thirdQuartile

    Three quarters have played.

  5. 100%complete

    The ad has played to the end.

Because every event carries an HMAC signature, a quartile call that has been altered or invented fails verification on return. The quality tracker also reads the sequence as a whole. An ad that reports complete without ever reporting start is a signal worth flagging, as is a run of completions arriving faster than the ad is long.

Where the player supports them, skip, pause, mute and click events can be tracked in the same way.

A path with milestones from start to a finish flag
07

Reporting on every tracked event.

Impression, quartile and other event tracking feeds a wide range of reports. We support reports by geography, app, bundle and more, and each event is recorded with consistent identifiers so any two views reconcile.

Dashboard cards with a map pin, a bar chart and an app icon grid

Geo reports

Delivery, impressions and quartile events broken out by country and region, using IP intelligence.

Country · Region

App and bundle reports

Results by app name and bundle or package ID, for mobile and CTV apps.

App · Bundle ID

Site and domain reports

The same view for web video, grouped by site or domain.

Site · Domain

Placement reports

Performance by placement or ad unit, so weak spots are easy to find.

Placement · Ad unit

Device and OS reports

Splits by device type, operating system and connected-TV platform class.

Device · OS · CTV platform

Campaign and creative reports

Delivery and event counts per campaign and creative, matched to your allocation weights.

Campaign · Creative

Quartile and completion reports

The full path from start through 25%, 50% and 75% to complete, with drop-off at each step.

Start → Complete

Reconciliation reports

Delivery against impressions, and AdStack counts against third-party tracker counts.

Delivery · Impression · Third-party

Quality and fraud-signal reports

Failed signatures, flagged requests and the signals behind each decision.

Signals · Outcomes

Reports can be cut by date and hour as well. Need a view that is not listed? Custom reports and export formats are agreed during integration.

Questions

Platform questions.

How does weighted delivery decide which campaign is served?

Each eligible campaign has a weight. Its share of delivery is its weight divided by the total of all eligible weights. Campaigns that fail a geography rule, cap or policy check are removed first, and the remaining weights are recalculated.

What is HMAC signing and why does it matter for tracking?

HMAC is a keyed hash. AdStack signs tracking URLs with a secret key and verifies the signature when the event returns. If the parameters have been altered or fabricated, the signature will not match and the event is rejected or flagged.

How does AdStack use MaxMind?

MaxMind IP intelligence supports IP detection and geographic or policy decisions at request time. Results are treated as strong signals rather than certainties, because accuracy varies by region and connection type.

Can AdStack guarantee zero fraud?

No. AdStack monitors fraud signals and uses them in decisioning, but no system removes invalid traffic entirely. Thresholds and responses are agreed for each integration and reviewed over time.

Why run more than one tracker?

Separate delivery, impression, event and quality trackers answer different questions. When their counts diverge, the gap is itself a useful signal for investigation and reconciliation.

What reports does AdStack support?

AdStack supports a wide range of reports built on impression, quartile and other event tracking: by geography, app and bundle ID, site and domain, placement, device and OS, campaign and creative, plus quartile and completion funnels, reconciliation against third-party trackers, and quality and fraud-signal views. Custom reports and export formats are agreed during integration.

Want to see how this maps to your traffic?

Share your environment and rough volumes. We will walk through how weighting, signing and tracking would apply.

WhatsApp us