Infrastructure
- Hosted on Vercel with managed Postgres and object storage in the EU/UK region.
- All traffic encrypted in transit (TLS 1.2+). Data encrypted at rest.
- Daily automated database backups retained 30 days; restore procedures tested.
Your social accounts
- We connect via official OAuth. We never ask for, see or store platform passwords.
- Access tokens are stored encrypted and refreshed proactively; you can disconnect any account instantly.
- Tokens nearing expiry trigger a warning to you 7 days ahead, so nothing fails silently.
Application security
- Role-based access control across workspaces; approval links are cryptographically random, expiring and revocable.
- Payments handled entirely by Stripe (PCI-DSS Level 1). Card data never touches our servers.
- Error monitoring with alerting; dependency and vulnerability scanning in CI.
Compliance posture
We are GDPR-compliant by design (see GDPR). We are early-stage and honest about it: formal security audits are planned as the team grows. If a certification claim isn’t on this page, we don’t claim it.
Responsible disclosure
Found a vulnerability? Email security@socialpro.app. We acknowledge within 48 hours, keep you updated, and credit researchers who report in good faith. Please don’t access other users’ data or degrade the service while testing.
Template notice. This page was prepared for Title Productions Ltd (t/a SocialPro) and reflects intended practice at launch.