Skip to content
post.social

Security

Security is part of the data model

PostSocial separates ownership, credentials, editable content, and historical delivery records instead of relying on hidden URLs alone.

Encrypted credentials

OAuth tokens, bot tokens, and Application Passwords are encrypted at rest and stored separately from public account metadata.

Project isolation

Workspace ownership and Project policies protect accounts, posts, media, schedules, and history from cross-Project access.

Safe identifiers

Public ULIDs are used outside the database; internal numeric IDs and credential fingerprints are not exposed.

Controlled provider access

Provider API keys remain in server configuration and are never returned to React, browser APIs, snapshots, or ordinary logs.

Auditable history

Final publication status, target identity, snapshot, timestamps, and credit ledger records are retained for operational audit.

Stripe-hosted payments

PostSocial uses Stripe for payment processing and does not store full payment-card details.

Responsible reporting

Found a security issue?

Please report it privately with enough detail for us to investigate. Do not access other users’ data or disrupt the service.

Email security

Truthful security statement

This page does not claim certifications, penetration-test results, uptime guarantees, or a formal bug bounty that PostSocial has not established.

Ready to simplify your publishing?

Start with a 14-day trial. No card required.

Start free trial