Skip to content

Security

What we do to protect your accounts and your customers' messages

This page says what is in place today, in plain terms. It also says what we do not claim, because a security page that only lists good news is not worth reading.

In place today

Encryption in transit and at rest for connected logins, separate workspaces checked on every request, verified webhooks, and payments handled entirely by Stripe.
  • HTTPS everywhere
  • AES-256-GCM at rest
  • Hashed API keys
  • Signed webhooks
  • Audit log

15 min

is how long a sign-in link lasts. There are no passwords to leak.

48 h

to tell customers whose data we process about a breach, from when we become aware of it.

What is in place

Encrypted in transit

All traffic to the app and its API uses HTTPS.

Connected logins are encrypted at rest

Access tokens, app passwords and keys you connect are stored with AES-256-GCM encryption. They are used only to publish, read statistics and answer messages, as you asked.

No passwords for sign-in

You sign in with Google or a single-use emailed link that expires in 15 minutes. Sessions use signed, HttpOnly, SameSite cookies and last 30 days.

Workspaces are separate

Every request is checked against the caller’s workspace, role and brands. Another workspace’s record looks the same as one that does not exist. An automated test checks every page, API route and action for this.

Roles

Owner, admin, editor and viewer, plus per-brand access. API keys carry a role and optional brand limits, and are stored only as a hash. You see a key once, when you make it.

An audit log

Administrative actions, billing changes and data exports are recorded with who did them.

Webhooks are verified

Messages from Meta, Stripe and our scheduler are accepted only with a valid signature.

Safe fetching of web addresses

When the app fetches a URL you gave it (an image, an RSS feed, a link check), it refuses private and internal addresses and re-checks every redirect.

Rate limits

Sign-in link requests, API calls and AI requests are rate-limited, so abuse and runaway scripts are slowed down.

Payments never touch our servers

Stripe handles cards. We never see or store card numbers.

Minimal data from messages

Inbox messages are kept for a year by default, or a shorter period the workspace owner chooses.

Deletion that finishes

Deleting a workspace erases it after a 14-day grace period, and backups roll over within 30 days after that.

What we do not claim

So you can decide with accurate information.

  • We do not hold a SOC 2 or ISO 27001 certificate. If you need one for procurement, we are not the right fit yet.
  • We run on Vercel and Neon rather than our own data centres. Their physical and network security applies; see the subprocessors page.
  • The database is not end-to-end encrypted: we can technically read the content of your workspace. We do so only to give support you asked for, to fix an error that stopped an automated process, to protect the service, or when the law requires it.
  • No service is free of vulnerabilities. If we have a breach affecting your data, we will tell you without undue delay, and within 48 hours of becoming aware for customers whose data we process on their behalf.

Report a vulnerability

If you have found a security problem, tell us before you tell anyone else.

Email info@builtwithskills.com with what you found, how to reproduce it, and what you think the impact is. Use the subject line “Security”.

We will acknowledge your report, keep you informed while we fix it, and credit you if you want. Please do not access other people's data beyond what is needed to show the problem, do not run tests that degrade the service, and give us reasonable time to fix it before disclosing. We will not take legal action against good-faith research that follows these rules.

Questions about how your data is handled?

The privacy policy and data processing agreement go into the detail.