Last updated: 8 September 2026
On this page
1. Scope
2. Infrastructure
3. Encryption
4. Access control and tenancy
5. Connected social accounts
6. Data handling
7. Application and platform security
8. Monitoring and availability
9. Incident response
10. Sub-processors
11. Compliance
12. Scope of the Service — regulated data
13. Shared responsibility
14. Vulnerability disclosure
15. Contact
Sociali — Security
Sociali manages social media content and connected accounts for multi-brand teams and agencies. Protecting that data is central to the product. This page describes the security measures we have in place.
For security questionnaires, penetration test requests, or architecture discussions, contact security@sociali.ai.
1. Scope
This policy covers the Sociali production application at sociali.ai, its supporting services, and the data our customers entrust to us.
2. Infrastructure
Sociali runs entirely on managed, audited cloud infrastructure in the United States.
Layer
Provider
Region
Application and edge network
Vercel
United States
Database, authentication, object storage
Supabase (on AWS)
United States
Supporting services and compute
Google Cloud Run
us-central1
Background job orchestration
Inngest
United States
We do not operate our own data centres or physical servers. Physical and environmental security is inherited from these providers, each of which maintains its own SOC 2 and ISO 27001 programmes.
3. Encryption
In transit
TLS 1.2 or higher on all public endpoints, with HTTPS enforced
At rest
AES-256 at the database and object-storage layer
Social account tokens
Additionally protected with application-layer authenticated encryption (libsodium/pgsodium) using a per-row nonce, decrypted only through a restricted database view
Secrets
Held in Google Secret Manager and Vercel encrypted environment variables, injected at runtime and never committed to source control
4. Access control and tenancy
Multi-tenancy. Sociali is brand-scoped by design. Every record belongs to a brand, every route is brand-scoped, and access is checked against the requesting user’s membership and role in the authorisation layer on every request.
Role-based access control. Brand owners and administrators assign roles that govern what each team member can see and do — including who may connect channels, create content, approve it, and publish.
Authentication. Accounts are authenticated through Supabase Auth. Passwords are stored as bcrypt hashes and never in plaintext.
Multi-factor authentication. Time-based one-time password (TOTP) multi-factor authentication is available to all users and can be required at session level.
Cross-site request forgery protection is applied at the edge across the application.
Sessions are managed and refreshed server-side.
5. Connected social accounts
Channels are connected through each platform’s official OAuth flow. Sociali never asks for or stores a customer’s social media password.
Tokens are stored encrypted (§3) and used only to perform the actions you request.
We request the minimum scopes needed for the features you use; the platform’s own consent screen shows exactly what is granted.
Disconnecting a channel revokes the token and stops all further access immediately.
Our use of data received from these APIs adheres to each platform’s developer and platform-data policies, including the Meta Platform Terms, LinkedIn API Terms, TikTok Developer Terms, and the Google API Services User Data Policy including its Limited Use requirements.
6. Data handling
You own your data. Customers retain all rights to the content, assets, and connected-account data in their workspace — see §4 of the Terms of Service.
No training on customer content. We contractually prohibit our AI providers from using customer content to train their general-purpose models.
No sale of data. We do not sell personal data and do not share it for cross-context behavioural advertising.
Payment data. Card details are collected and processed entirely by Stripe, a PCI DSS Level 1 service provider. Sociali never receives, transmits, or stores full card numbers, which keeps cardholder data out of our environment.
Data location. United States. [Confirm before publishing whether to state a roadmap position on EU/UK data residency.]
Export and deletion. Customers can export their data through the application, and can request deletion in line with the Privacy Policy.
7. Application and platform security
Input validation using typed schemas on application requests.
Code review — all changes go through pull request review before merge.
Automated CI gates — linting, TypeScript type checking, and automated test suites run on every change.
Separate environments — development and production run as fully separate projects with separate credentials.
Dependency monitoring — automated dependency update and vulnerability alerting across our repositories.
Least privilege — services are granted only the cloud permissions they require.
8. Monitoring and availability
We monitor the platform continuously for errors, performance regressions, and infrastructure health, with alerting to the engineering team.
Application error and performance monitoring
Infrastructure and service metrics
Automated alerting to an engineering channel
Backups. The database is backed up automatically by our managed database provider, with point-in-time recovery available.
9. Incident response
We investigate suspected security incidents promptly and prioritise containment, remediation, and customer communication.
Breach notification. If a personal data breach affects customer data, we will notify affected customers without undue delay, and in any event within 72 hours of becoming aware where notification is required — with the information needed for customers to meet their own obligations. See the Privacy Policy and DPA.
10. Sub-processors
We publish the full list of sub-processors, including each vendor’s purpose, the categories of data processed, and its location, at https://sociali.ai/subprocessors.
We give 30 days’ advance notice before adding or replacing a sub-processor that processes customer data. Customers can subscribe to those notices at privacy@sociali.ai.
11. Compliance
12. Scope of the Service — regulated data
Sociali is a social media marketing platform. It is designed for content that is intended for publication, and is not configured to hold regulated health, payment, or identity data.
Customers should not submit to the Service: protected health information (PHI) subject to HIPAA; cardholder data; government-issued identifiers; biometric identifiers; or special category personal data under GDPR Article 9.
Customers in healthcare, senior living, and wellness should use Sociali for public-facing marketing content only. Sociali does not act as a HIPAA Business Associate.
Full details are in the Acceptable Use Policy §4.
13. Shared responsibility
Security is a partnership. Customers are responsible for:
enabling multi-factor authentication and managing team access, including removing users who leave;
keeping connected channel permissions current and disconnecting channels no longer in use;
reviewing AI-generated content before publication;
complying with the Acceptable Use Policy;
configuring approval workflows appropriately for their own risk tolerance.
14. Vulnerability disclosure
We welcome reports from security researchers and will work with you in good faith.
Report to: security@sociali.ai
Please do
test only against accounts you own or have permission to test;
report promptly, with enough detail to reproduce the issue;
allow us 90 days before public disclosure.
Please do not
access, modify, or exfiltrate data belonging to others;
degrade the Service — no denial-of-service, no high-volume automated scanning;
use social engineering or physical attacks.
Safe harbour. If you follow this policy in good faith, we will not pursue or support legal action against you, and we will consider your research authorised under the Computer Fraud and Abuse Act and equivalent laws.
Our commitment. We will acknowledge your report within 3 business days, triage it within 10 business days, and keep you updated until it is resolved. We are glad to credit researchers publicly.
15. Contact
Sociali LLC · 1023 E Lincolnway, Cheyenne, Wyoming 82001, United States