Security
Provider tokens and vault secrets are encrypted at rest. The application uses scoped organization access, short-lived access sessions, rotating refresh sessions, OAuth state verification, signed Meta deletion requests, restricted media paths, and authenticated background-job endpoints.
Report a vulnerability or incident
Send security reports to suriya@dsignxt.com. Include a clear description, reproduction steps, and impact. Do not include live access tokens, passwords, or unnecessary personal data. Please avoid privacy violations, destructive testing, service disruption, and accessing data that is not yours.
If you believe Meta Platform Data was exposed, report it immediately so the operator can investigate, contain the issue, notify affected parties and Meta where required, and revoke affected credentials.