Trust & security

Security practices

Our platform is built to keep OAuth, publication workflows, and tenant boundaries secure by default.

Official Google OAuth integration
Tokens encrypted at rest
Explicit user consent required
  • OAuth state + PKCE validation on connect/callback flow.
  • Server-side encrypted token storage (no browser token persistence).
  • Trace-id based audit trail for connect/disconnect/publish actions.
  • Least-privilege Google scopes for Business Profile operations.
  • Role-aware organization access checks on critical endpoints.