<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=134132097137679&amp;ev=PageView&amp;noscript=1">

Pixalate Expands Programmatic CTV App Pre-Bid Blocklist: Flags Known Dangerous & Fraudulent Publishers Based on Historical IVT Rates, App-Ads.txt, App Store ToS, & Privacy Compliance Risk Ratings

Aug 14, 2026, 6:00:00 AM

Pre-bid blocklist updated daily and available through AWS RTB Fabric, APIs, FTP, and S3

LONDON, August 14, 2026Pixalate today introduced the High Risk Apps (HRA) CTV app pre-bid blocklist for the programmatic advertising industry. The blocklist identifies known dangerous and fraudulent CTV apps by combining persistent invalid traffic (IVT) signals, app store compliance indicators, app-ads.txt authorization checks, and privacy risk signals into a unified feed with 9 clear risk reason codes.

The blocklist is a daily-updated list of CTV apps — across 9 operating systems including Android, FireOS, Linux, Roku, Samsung, Sony, tvOS (Apple TV), LG webOS, and Windows — that buyers and sellers use to exclude apps from programmatic ad campaigns before a bid is placed.

Traditional ad fraud detection started from scratch on every impression, with each bid evaluated in isolation and disconnected from historical signals. The blocklist aligns with Media Rating Council (MRC) guidance to use lists of “known dangerous or fraudulent sources” in addition to impression-level IVT classifications.

The blocklist is built on Pixalate's daily monitoring of 378,622 CTV app-platform pairs — spanning hundreds of device and platform variants that map to 9 major CTV app stores including Roku, Fire TV, Samsung, and Apple TV — covering 52,102 unique apps.

High Risk CTV Apps Blocklist: 9 Risk Reason Codes

The CTV HRA pre-bid blocklist evaluates each app against 9 risk dimensions.

Risk Type*

Code

Description

High GIVT

highGivt

Apps with General Invalid Traffic rates exceeding 5% over a 3-month rolling window

High SIVT

highSivt

Apps with Sophisticated Invalid Traffic rates exceeding 15% over a 3-month rolling window

Missing Privacy Policy

missingPrivacyPolicy

Apps missing privacy policy URLs on the official app store page and website, per Pixalate’s analysis

Abandoned App

abandonedApp

Apps that have not been updated by developers in 3+ years and may be unmaintained, insecure, or non-compliant with current app store requirements

Missing app-ads.txt

noAdsTxt

Apps generating ad impressions without a valid app-ads.txt file, indicating unauthorized inventory

Developer Anonymity

developerAnonymity

Apps where the developer has missing or unverifiable contact information

VPC Bypass Risk

vpcBypass

Child-directed apps transmitting personal data without Verifiable Parental Consent, creating COPPA compliance exposure

Delisted App

delistedApp

Apps removed from app stores that continue to generate ad traffic

Made for Advertising

mfaApp

Apps designed primarily to generate ad impressions rather than deliver genuine user value, including apps exhibiting ad stacking and other manipulative ad placement tactics

 

*Risk Type coverage differs across CTV operating systems based on each platform’s level of transparency and metadata availability.

Each app is tagged with one or more risk reason codes. When an app is flagged for multiple risk types, all applicable codes are visible. This enables buyers to build selective blocking logic.

App-Level Risk vs. Traffic-Level Risk

The CTV HRA blocklist separates app-level structural risk from impression-level IVT classification. This aligns with the Media Rating Council’s Invalid Traffic Detection and Filtration Interim Update Memo, which distinguishes impression-level IVT measurement from property-level risk reporting.

Impressions from apps on the High Risk CTV Apps list are not automatically classified as IVT. IVT is now reported only when impression-level invalid signals are detected.

This means IVT reporting reflects impression-level measurement, and app-level risk is reported independently, giving buyers independent control over app-level blocking and impression-level filtering.

Use Cases

For SSPs & Exchanges

  • Ad fraud management: Remove apps where IVT is material, persistent, and inseparable from legitimate traffic.
  • Selective blocking: Use risk reason codes to apply selective blocking based on risk tolerance and publisher relationships.
  • Measurement accuracy: Surface app-level risk independently from impression-level IVT reporting to preserve measurement accuracy.

For DSPs & Agencies

  • Pre-bid filtering: Exclude flagged App IDs from campaign targeting.
  • Compliance: Block apps flagged for Missing Privacy Policy, VPC Bypass Risk, or Delisted Apps to reduce regulatory exposure.
  • Brand safety: Prevent ad spend from reaching MFA apps, abandoned apps, and developers with unverifiable identities.

 

Data Schema

Column

Type

Description

appId

STRING

The actual ID that characterizes a CTV app, if available

bundleId

STRING

The bundle ID associated with the app

osName

STRING

The Operating System (OS) name that is associated with a given app

platformName

STRING

The platform where the CTV app is available

riskType

STRING

Comma-separated list of all applicable risk type codes (e.g., highSivt,abandonedApp,missingPrivacyPolicy)

 

Availability

High Risk CTV Apps blocklist is available as a daily CSV feed delivered through AWS RTB Fabric, APIs, FTP, or S3 bucket through Pixalate’s Pre-Bid Blocking Data Feeds.

App-level risk indicators are also surfaced in Pixalate’s Analytics dashboard, including a boolean indicator that shows if an app is flagged on HRA and a share of voice of traffic on apps flagged via HRA.

Contact Pixalate to learn more.

About Pixalate

Pixalate is a global platform specializing in privacy compliance, ad fraud prevention, and digital ad supply chain data intelligence. Founded in 2012 and recognized by UNICEF as a “key innovator” for children’s online privacy, Pixalate is trusted by regulators, data researchers, advertisers, publishers, ad tech platforms, and financial analysts across the Connected TV (CTV), mobile app, and website ecosystems. Pixalate is accredited by the MRC for the detection and filtration of Sophisticated Invalid Traffic (SIVT). pixalate.com

Disclaimer

The content of this press release reflects Pixalate’s opinions with respect to factors that Pixalate believes may be useful to the digital media industry. Any data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate’s opinions are just that, opinions, which means that they are neither facts nor guarantees. Pixalate is sharing this information and any associated data not to impugn the standing or reputation of any entity, person or app, but, instead, to report findings and trends pertaining to programmatic advertising activity in the time period studied.

Per the MRC, “‘Fraud’ is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes. Also per the MRC, “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.”

Search Blog

Follow Pixalate

Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our Terms of Use and Privacy Policy.

Subscribe to our blog

*By entering your email address and clicking Subscribe, you are agreeing to our Terms of Use and Privacy Policy.