Skip to content
PubTrust — a ClearTrust product · cleartrust.ccAd quality and malvertising protection for publishers

Company

Frequently asked questions

Grouped by the thing you are actually trying to find out.

The product

What is PubTrust?

PubTrust is publisher-side ad-quality and malvertising protection. You install one script tag; it watches every ad slot on your pages, judges each creative against your policy before the browser paints it, blocks what violates that policy, paints your own fallback creative in the slot instead, and reports the catch with full forensic detail. It is a product of ClearTrust.

How is this different from an ad blocker?

An ad blocker works for the reader and removes advertising indiscriminately. PubTrust works for the publisher and removes a small, specific subset of advertising — creatives that attack readers or violate the publisher's own policy — while leaving everything else to monetise normally. By area, the mark on this site is mostly window and only a corner of blade, which is an accurate picture of the ratio.

How is this different from DoubleVerify or IAS?

Different side of the transaction and a different question. DV and IAS largely serve advertisers, measuring whether an impression was real and whether it appeared in a suitable place. PubTrust serves publishers and stops a creative from executing on your page. They are not competitors and PubTrust sits alongside them without conflict.

Does PubTrust work with my ad stack?

Prebid.js and Google Publisher Tag are supported directly, and a generic window.__ptSlots bridge covers custom stacks — including pre-render coverage if you pass the creative markup. Direct-sold inventory with no bid metadata is covered by the DOM and runtime layers.

Can I preview what a creative looked like?

Where we legally hold one, yes — captured server-side in a headless browser as part of deep scan. We do not and cannot capture a cross-origin creative from a reader's browser; that is impossible, and we would rather explain why than imply otherwise.

Blocking and accuracy

Does blocking cost me revenue?

Less than the intuition suggests, and we show you exactly how much. Google Ad Manager counts an impression on begin-to-render, so a creative blocked before render was never counted and never earned — nothing was lost. Every block PubTrust makes carries an estimated revenue impact based on the winning bid's CPM at the moment of decision, and every policy carries a running total, so the cost of protection is a figure you watch rather than a number you argue about.

What is your detection rate?

We do not publish one, and we would be suspicious of anyone who does. There is no MRC or IAB standard definition of a malicious creative to measure a rate against — the MRC's Brand Safety Ad Verification Supplement does not contain the words "malvertising", "malicious", "malware" or "creative" — so any published percentage is measured against a definition the vendor chose. We would rather give you the mechanism, the rule that fired and the latency, and let you test it on your own inventory during a trial.

What happens when you block something you should not have?

You see the exact rule, the matched value and its weight on the violation row, and you allowlist it in one click at advertiser, creative or rule level. You can also lower that rule's weight in your own policy without touching anything else. Because every new site is in Monitor mode, your first weeks of false positives cost you nothing, which is the entire point of Monitor.

How fast is the decision?

Measured in the tag, reported with every beacon and shown in your dashboard at median and p95, per site and per layer. Most decisions require no network round trip at all — the policy bundle carries a precomputed verdict cache, so a creative the network has already condemned is blocked on a lookup. We are not going to print a number on this page that we cannot reproduce on your inventory; we are going to show it to you in your own dashboard, which is more than this category currently does.

Will PubTrust slow down my page?

The tag is 11.4 KB gzipped, loads async, and puts nothing synchronous on your critical path. It is served from Cloudflare's global edge, as is the policy bundle — which is immutable, content-addressed and shared across every publisher on that policy version, so it typically resolves from cache rather than from an origin. Blocking uses visibility:hidden rather than display:none, so Cumulative Layout Shift from a block is zero.

What happens if your tag throws an error?

It goes dormant and your page carries on. Every hook is wrapped in try/catch; a watchdog unhooks everything at once and reports if the tag throws too often or exceeds its CPU budget; a remote kill switch can disable a build globally within about five minutes with no deploy from you; and window.__ptDisable = true is your own permanent escape hatch.

Languages and markets

Which languages are supported?

Fourteen: en, de, fr, es, it, pt, nl, sv, da, no, fi, pl, cs, tr. Each is a natively authored corpus with its own regulatory context and documented false friends, not a translation of the English list.

Do you support Chinese, Japanese, Korean, Arabic or Hebrew?

Not at launch, and we say so rather than letting you discover it. For inventory in those languages the keyword packs under-read. Everything language-independent still works at full strength: Runtime Integrity, pre-render bid metadata, domain and URL rules, and the server-side verdict cache.

Will you block licensed gambling operators I actually want?

Not by default. Svenska Spel, ATG, Norsk Tipping, Norsk Rikstoto, Danske Spil, Veikkaus, Totalizator Sportowy, FDJ, PMU, Sazka, Tipsport, Lottomatica, Holland Casino and their peers are lawful advertisers in their own markets, and their brand terms are weighted at or below 0.5 in our corpus specifically so the Gambling pack cannot fire on them alone. A publisher who wants them blocked raises the weight; a publisher who wants them allowed adds one allowlist entry.

Why does a blanket gambling block not work in the US?

Because US legalisation is state by state and still changing, so the same operator can be a licensed advertiser in one state and unlawful in the next. PubTrust carries country, region and city on every violation, so you can enforce at whatever granularity your commercial and legal position requires rather than flipping one national switch.

Privacy and compliance

Do you collect my readers' IP addresses?

Not in full, by default. IPs are truncated at the edge before storage — IPv4 to /24, IPv6 to /48 — so the full address is never written to our database and is never available to our staff. We keep country, region, city, ASN and network operator, which is what malvertising forensics actually need. Full-IP retention is per-organisation opt-in, requires explicit acknowledgement and has a 30-day hard cap.

Do you set cookies or track readers?

No cookies, no localStorage, no fingerprinting, no device or user identifier, and nothing that can link a reader across two of your sites.

Are you GARM compliant?

No, and neither is anybody else. GARM was discontinued in August 2024 and the WFA confirmed in July 2026 that it will not be restarted. We report against IAB Ad Product Taxonomy 2.0 — Gambling is node 1361, cryptocurrency 1448/1449 — and carry IAB Content Taxonomy 3.1 for page context, including the Sensitive Topics branch where the former GARM Brand Safety Floor categories now live in maintained form.

Does PubTrust help with DSA compliance?

It gives you the record underneath it. For every creative on your inventory you get the declared advertiser domain, the domain we observed, the bidder, the creative identifier, the landing destination and the category — retained, queryable and exportable. The Political pack detects the mechanics of paid electoral advertising so you can label, route or withhold it. We do not file your disclosures, and any vendor claiming to make you "DSA compliant" by installing a tag is overselling.

Can I see what your support staff did in my account?

Yes. Impersonation requires a typed reason, is time-limited, is read-only unless a second explicit confirmation is given, shows the staff member a permanent banner, and appears in your audit trail as well as ours. Both the acting user and the impersonator are recorded on every affected row.

Commercial

What counts as a hit for billing?

One pageview on a protected site — not one ad slot and not one impression. A page with six slots is one hit. The count comes from a summary beacon carrying exact counts computed on the page, not from a sampled estimate, so your invoice is derived from something your reader's browser actually counted.

What happens if I exceed my plan?

We email at 80% and 100% and bill the overage. We do not turn off protection for a billing problem. Past a hard limit we reduce clean-impression sampling and lock report export; blocking keeps running. Turning off a security control because an invoice is late converts a payment issue into a malvertising incident.

Is there a trial?

Fourteen days, no card. Since sites start in Monitor, the trial is useful on its own merits: you get two weeks of real, priced violation data on your real inventory whether or not you buy.

How do I remove PubTrust?

Set the site to Off and running tags go inert at their next configuration poll, within about five minutes, with no deploy. Or set window.__ptDisable = true. Or delete the script tag. A vendor who is hard to remove should not be trusted with your pages.