Security

Your accounts are in safe hands

WePost holds the keys to your social accounts, and we treat that responsibility seriously. Here is how we protect them.

Tokens encrypted at rest

Platform access and refresh tokens are encrypted with AES-256-GCM, using keys that can be rotated. They are decrypted only by the services that publish for you, are never returned by our API, and are scrubbed from logs and error reports.

Least-privilege access

We request only the OAuth scopes that shipped publishing features need, record exactly what each account granted, and never ask for access to private messages.

Strong sign-in

Passkeys and two-factor authentication for your team, with two-factor authentication required for administrators. Sessions can be revoked at any time.

Workspace isolation

Every request is scoped to a workspace, and automated tests check that no workspace can reach another’s data.

Verified integrations

Incoming platform notifications are signature-checked, outgoing webhooks are signed with HMAC-SHA256, and media imports are protected against server-side request forgery.

Audit trail

Connects, disconnects, API key changes, publishes and deletions are recorded in each workspace’s audit log.

Responsible disclosure

Found a vulnerability?

Please email security@wepo.st with a description, steps to reproduce and the impact you observed. We will acknowledge your report within three business days and keep you updated until it is resolved.

Please

  • Give us reasonable time to fix the issue before disclosing it publicly.
  • Only test against accounts and data you own.
  • Avoid privacy violations, data destruction and service disruption.
  • Do not use social engineering, physical attacks or denial-of-service testing.

We will not pursue legal action against researchers who act in good faith and follow these guidelines. Our contact details are also published in security.txt.

More about your data

Read our Privacy Policy for what we collect and how long we keep it, and Data Deletion for how to remove your data. Questions: security@wepo.st.