Security

Security practices behind Wizspeed Social

We treat every connected account and every workspace's data with the same care as our own — here's how that works in practice.

How we protect your accounts

Account connections and data handling

OAuth account connections

Every social account is connected through that platform's official authorization flow — we never ask for platform passwords.

Token encryption

Access tokens are encrypted at rest and only decrypted server-side when a request needs to be made.

Tenant isolation

Each workspace's accounts, content and data are logically separated from every other workspace.

Secure server-side requests

Publishing and data fetches run from our servers through official APIs, never from a user's browser.

Access controls

Role-based permissions decide who can view, draft, approve or publish within a workspace.

Audit logging

Key actions — connections, publishes and approvals — are recorded for workspace owners to review.

Publishing safeguards

Controls before content goes live

Approval workflows

Route drafts through the right reviewers before anything publishes.

Scoped permissions

Limit who can connect accounts, publish or manage a client workspace.

Revocable connections

Disconnect an account at any time to immediately stop access.

Privacy principles

How we think about your data

  • Data is used to operate the workspace you configure — not sold to third parties.
  • Client workspaces stay isolated from one another inside an agency account.
  • You can disconnect accounts or delete workspace data at any time.
  • We work only through official, platform-compliant APIs.
Responsible disclosure

Found a security issue?

Report a vulnerability

If you believe you've found a security issue, please contact our security team so we can investigate promptly.

security@wizspeed.social

Ready to connect your accounts?

Start free and see the workspace for yourself.