Encrypted credentials
OAuth tokens, bot tokens, and Application Passwords are encrypted at rest and stored separately from public account metadata.
Security
PostSocial separates ownership, credentials, editable content, and historical delivery records instead of relying on hidden URLs alone.
OAuth tokens, bot tokens, and Application Passwords are encrypted at rest and stored separately from public account metadata.
Workspace ownership and Project policies protect accounts, posts, media, schedules, and history from cross-Project access.
Public ULIDs are used outside the database; internal numeric IDs and credential fingerprints are not exposed.
Provider API keys remain in server configuration and are never returned to React, browser APIs, snapshots, or ordinary logs.
Final publication status, target identity, snapshot, timestamps, and credit ledger records are retained for operational audit.
PostSocial uses Stripe for payment processing and does not store full payment-card details.
Responsible reporting
Please report it privately with enough detail for us to investigate. Do not access other users’ data or disrupt the service.
Email securityThis page does not claim certifications, penetration-test results, uptime guarantees, or a formal bug bounty that PostSocial has not established.