Security Policy

Last Updated: July 2, 2026

1. Secure Token Storage

We take token security very seriously. All OAuth Access Tokens and Page Access Tokens retrieved from Meta are encrypted at rest in our MongoDB databases. Even in the event of database access leakage, the raw tokens cannot be decoded without the decryption keys stored on isolated server environments.

2. Webhook Signature Verification

To prevent spoofing or unauthorized payload delivery, every incoming webhook request from Meta is validated in real-time. Our verification middleware validates the payload hash signature using the App Secrets corresponding to your apps before processing the events.

3. TLS / HTTPS Encryption

All network traffic between our servers and Meta is fully encrypted using SSL/TLS protocols. We do not accept unencrypted webhook callbacks or send plain-text token exchanges.

4. Dynamic Revocation & Self-Service Wipe

Users maintain full control over their secure credentials. Clicking "Disconnect" on any connected Instagram account immediately deletes the access token permanently from our databases and discontinues further messaging execution.