Security practices behind Wizspeed Social
We treat every connected account and every workspace's data with the same care as our own — here's how that works in practice.
Account connections and data handling
OAuth account connections
Every social account is connected through that platform's official authorization flow — we never ask for platform passwords.
Token encryption
Access tokens are encrypted at rest and only decrypted server-side when a request needs to be made.
Tenant isolation
Each workspace's accounts, content and data are logically separated from every other workspace.
Secure server-side requests
Publishing and data fetches run from our servers through official APIs, never from a user's browser.
Access controls
Role-based permissions decide who can view, draft, approve or publish within a workspace.
Audit logging
Key actions — connections, publishes and approvals — are recorded for workspace owners to review.
Controls before content goes live
Approval workflows
Route drafts through the right reviewers before anything publishes.
Scoped permissions
Limit who can connect accounts, publish or manage a client workspace.
Revocable connections
Disconnect an account at any time to immediately stop access.
How we think about your data
- Data is used to operate the workspace you configure — not sold to third parties.
- Client workspaces stay isolated from one another inside an agency account.
- You can disconnect accounts or delete workspace data at any time.
- We work only through official, platform-compliant APIs.
Found a security issue?
If you believe you've found a security issue, please contact our security team so we can investigate promptly.
Ready to connect your accounts?
Start free and see the workspace for yourself.