Security & Trust

Your accounts and content, protected

Security isn’t bolted on at the end, it’s built into how the platform connects accounts, isolates data and controls who can do what.

How we protect you

Security at every layer

From the moment you connect an account to the moment content publishes, your data is encrypted, isolated and access-controlled.

Encrypted credentials

Social and CMS access tokens are encrypted at rest with AES-256-GCM and decrypted only when needed to publish, never stored or logged in plain text.

OAuth, done right

Account connections use official OAuth flows with signed, single-use state and nonce protection to prevent CSRF and connection hijacking.

Per-workspace isolation

Every brand’s data lives in its own workspace, scoped by account owner and access-checked on every request, no cross-tenant leakage.

Granular access control

Role-based team permissions (Admin / Editor / Viewer) are scoped to specific workspaces and features, with per-feature read/write/delete control.

SSRF & abuse guards

Server-side URL fetches are validated against private and internal hosts, and sensitive endpoints are rate-limited to prevent abuse.

Secure billing

Payments are processed by Razorpay over secure, tokenized flows. We never see or store your full card details.

Data & privacy

You stay in control of your data

  • Disconnect any integration at any time, the associated tokens and synced profile data are removed, not just hidden.
  • Your content, analytics and connected accounts are scoped to your account and never shared across customers.
  • Team access is least-privilege by design: people see and act on only the workspaces and features they’re granted.
  • Review exactly how we handle data in our Privacy Policy, and our billing terms in the Refund Policy.

Encrypted at rest · Isolated per workspace

Have a security question?

Our team is happy to walk through how we handle your data, accounts and access controls.

No credit card  · Free AI credits included  · Cancel anytime