What is Brand Safety?

Brand safety is the set of rules and filters that keep a brand’s ads from appearing next to content that can damage reputation: violence, hate, pornography, terrorism, piracy, toxic comment threads. The object is adjacency — creative next to a page, video, or app — not click quality. In programmatic and open display, inventory is assembled automatically: without lists and verification, an ad can land on an MFA site, a contested news story, or a UGC app the advertiser does not control.

Brand safety vs brand suitability

Brand safety is closer to a binary ban: “nobody in the agency’s book runs next to this.” Brand suitability is brand-specific. A sports brand may accept a match-injury story; a children’s brand will not. An airline blocks crash coverage; a B2B news buy does not. IAB Content Taxonomy labels the page; the buyer chooses which tiers are allowed. The GARM alliance once aligned the industry around 11 “sensitive” topics — the organization shut down in 2024, but the categories (hate, misinformation, online piracy, and others) remain in briefs and DSP UIs.

Do not mix safety with ad moderation or platform policy. Moderation rejects the advertiser’s creative and landing (claims, banned verticals). Brand safety rejects the environment where that creative runs. The same finance ad can pass Google and still be pulled from publishers about payday loans and scandals if the brand asks.

Exclusion lists and allowlists

The basic tool is exclusion:

  • Keywords — block on words in the URL, title, or page body. False positives are common: “crash” hits both plane crashes and a stock drop; “shoot” hits crime and a photo shoot.
  • Domains and apps — URL/bundle blacklists. Easier to control than semantics, but the list goes stale.
  • IAB categories / topics — block whole rubrics (adult, weapons, politics).
  • Verifier segments — packaged floors such as “hate speech,” “unrateable,” “made for ads.”

An allowlist (inclusion) serves only approved domains and apps. Safer, narrower reach, higher CPM. In PMPs and programmatic guaranteed, lists are often part of the IO. Contextual targeting (page semantics, not a behavioural cookie) is used both to replace some keyword blocks and to stay in “safe” topics without a giant blacklist.

Next to IVT, not the same thing

Invalid traffic (IVT) is impressions and clicks with no real person, or with inflated activity: bots, datacenters, hijacked devices. That sits next to bot traffic and click fraud. Brand safety answers “what content did we sit next to?”; IVT answers “was there a user at all?” The same verification vendor (IAS, DoubleVerify, and peers) often sells both packs — hence mixed report columns. MFA sites can look clean on IVT and fail suitability: a person is there, the context is an ad farm.

Brand safety is not a guide to evading filters and not a walkthrough of inflation schemes. For a buyer it is a set of contractual limits plus GIVT/SIVT and adjacency reports, read against post-click CR — not “how to sneak onto a site.”

How it shows up in buying

Pre-bid: the DSP skips the auction if the URL/app is blocked or the verifier forecast is below the floor. Post-bid: the impression is already bought; the report flags it unsafe / unsuitable — spend is gone, optimization is after the fact. Google Ads and Meta bake in part of the control (content exclusions, publisher lists, inventory filters); DV360 adds those levers plus third-party segments. On native the risk is higher: the creative mimics editorial, so a scandalous headline hurts more than a footer banner.

In arbitrage and performance, brand safety usually arrives from the advertiser’s IO: no adult/news/UGC, a whitelist of GEOs and apps. A breach is not only a bruised brand: holds, rejected postbacks, the offer switched off. The other side: gambling, nutra, and dating themselves fall under large-brand exclusions and platform moderation. Publisher filters and buyer filters are different lists.

Limits

A harsh keyword block cuts reach and lifts CPM without lifting CR. Automatic categories misfire on satire, sports, and news. After cookie limits and GDPR, context and domain lists weigh more than behavioural audiences again. Safety does not measure viewability and does not replace fraud checks. Reports should show the share of impressions on flagged inventory and, separately, CR on those same domains in the tracker.

See also: programmatic advertising, display ads, ad moderation, policy violation, click fraud.