01

Data encryption

  • All data is encrypted in transit using modern TLS.
  • Sensitive information, including connection credentials, is encrypted at rest.
  • Encryption keys are managed separately from the data they protect.
02

Account & access

  • Accounts are protected with strong password requirements and support for multi-factor authentication.
  • Internal access to production systems is limited to authorized personnel on a need-to-know basis.
  • Administrative access requires multi-factor authentication.
03

Platform connections

  • PostTrail uses industry-standard OAuth to connect to third-party platforms.
  • We request only the permissions needed to publish on your behalf.
  • You can disconnect any platform at any time from your dashboard.
04

Content handling

  • You own your content. We process it only to operate the service for you.
  • We do not sell your content or use it to train third-party models.
  • When you remove content or close your account, we delete it from our active systems.
05

Infrastructure

  • PostTrail runs on reputable cloud providers that follow industry-standard security controls.
  • Production systems are monitored for availability and unusual activity.
  • Software dependencies are kept up to date with the latest security patches.
06

Incident response

  • We follow a documented response process for incidents that may affect the service.
  • If an incident affects your data, we will notify you in a timely manner with clear information.
  • We review our security practices regularly and improve them as we learn.
Responsible disclosure

Found a security issue?

We welcome reports from the security community. Please email contact@posttrail.social with details of what you found and how to reproduce it. We review every report and will respond as promptly as we can.

Please do not publicly disclose an issue until we've had a reasonable opportunity to address it.