Trust & security
Security practices
Our platform is built to keep OAuth, publication workflows, and tenant boundaries secure by default.
Official Google OAuth integration
Tokens encrypted at rest
Explicit user consent required
- OAuth state + PKCE validation on connect/callback flow.
- Server-side encrypted token storage (no browser token persistence).
- Trace-id based audit trail for connect/disconnect/publish actions.
- Least-privilege Google scopes for Business Profile operations.
- Role-aware organization access checks on critical endpoints.