Security

Your brand, your data, your control.

Tenant-isolated workspaces, encrypted social tokens, signed Stripe webhooks, idempotent credit accounting.

  • Encrypted tokens
  • Hard tenant isolation
  • No data resale

Security, SocialCTL isolates every account in its own tenant scope, encrypts your connected social tokens at rest, verifies Stripe webhook signatures, and makes credit accounting idempotent so duplicate events can never double-charge. Your prompts and generations stay in your workspace.

Encrypted tokens

Social account tokens are encrypted at rest and never exposed in views.

Tenant isolation

Every query is scoped — cross-tenant access is a hard 403.

Payment integrity

Stripe-signed webhooks, idempotent credit grants — duplicate webhooks cannot double-charge.

How we protect your workspace

Per-account isolation

A global tenant scope wraps every model; cross-account access returns a hard 403, not a leak.

Encrypted connections

OAuth tokens for your social accounts are encrypted at rest and never rendered in the UI.

Signed media links

Client review links use unguessable tokens with signed, time-limited media URLs.

Idempotent billing

Stripe webhook signatures are verified and credit grants are idempotent — a replayed event cannot charge you twice.

Made with SocialCTL

Real output, not stock

Every frame below was generated by SocialCTL from a brand kit and a one-line brief. No stock library, no shoot.

Reel / Short Video What Happens In The First 48 Hours After You Call Us...
Carousel 10 checks before your brand disappears from AI answe...
71% of companies say they run AI agents. 11% actually shipped.
Static Post 71% of companies say they run AI agents. 11% actuall...

Frequently asked.

Do you sell my data?
No. Your prompts and generations stay in your workspace and are not sold.
Are my social account tokens safe?
Yes — they are encrypted at rest and never exposed in any view or API response.
How are client review links secured?
Each link is a long, unguessable token with a configurable expiry, is revocable at any time, and serves media via signed, time-limited URLs — no client login required, no standing access.
Can one account see another account's content?
No. Every database query is tenant-scoped; a cross-account request is rejected with a 403.
How do you handle payments?
Payments run through Stripe. Webhooks are signature-verified and credit accounting is idempotent, so duplicate or replayed events can never double-charge.
How do I report a vulnerability?
Contact support with the details and we'll respond quickly and coordinate a fix.
Deep dive Read the complete guide

Your first calendar is on us.

No card. See what a month of content for your business looks like in 60 seconds.

Build my free calendar