Security
What we do to protect your accounts and your customers' messages
This page says what is in place today, in plain terms. It also says what we do not claim, because a security page that only lists good news is not worth reading.
In place today
- HTTPS everywhere
- AES-256-GCM at rest
- Hashed API keys
- Signed webhooks
- Audit log
15 min
is how long a sign-in link lasts. There are no passwords to leak.
48 h
to tell customers whose data we process about a breach, from when we become aware of it.
What is in place
Encrypted in transit
All traffic to the app and its API uses HTTPS.
Connected logins are encrypted at rest
Access tokens, app passwords and keys you connect are stored with AES-256-GCM encryption. They are used only to publish, read statistics and answer messages, as you asked.
No passwords for sign-in
You sign in with Google or a single-use emailed link that expires in 15 minutes. Sessions use signed, HttpOnly, SameSite cookies and last 30 days.
Workspaces are separate
Every request is checked against the caller’s workspace, role and brands. Another workspace’s record looks the same as one that does not exist. An automated test checks every page, API route and action for this.
Roles
Owner, admin, editor and viewer, plus per-brand access. API keys carry a role and optional brand limits, and are stored only as a hash. You see a key once, when you make it.
An audit log
Administrative actions, billing changes and data exports are recorded with who did them.
Webhooks are verified
Messages from Meta, Stripe and our scheduler are accepted only with a valid signature.
Safe fetching of web addresses
When the app fetches a URL you gave it (an image, an RSS feed, a link check), it refuses private and internal addresses and re-checks every redirect.
Rate limits
Sign-in link requests, API calls and AI requests are rate-limited, so abuse and runaway scripts are slowed down.
Payments never touch our servers
Stripe handles cards. We never see or store card numbers.
Minimal data from messages
Inbox messages are kept for a year by default, or a shorter period the workspace owner chooses.
Deletion that finishes
Deleting a workspace erases it after a 14-day grace period, and backups roll over within 30 days after that.
What we do not claim
So you can decide with accurate information.
- We do not hold a SOC 2 or ISO 27001 certificate. If you need one for procurement, we are not the right fit yet.
- We run on Vercel and Neon rather than our own data centres. Their physical and network security applies; see the subprocessors page.
- The database is not end-to-end encrypted: we can technically read the content of your workspace. We do so only to give support you asked for, to fix an error that stopped an automated process, to protect the service, or when the law requires it.
- No service is free of vulnerabilities. If we have a breach affecting your data, we will tell you without undue delay, and within 48 hours of becoming aware for customers whose data we process on their behalf.
Report a vulnerability
If you have found a security problem, tell us before you tell anyone else.
Email info@builtwithskills.com with what you found, how to reproduce it, and what you think the impact is. Use the subject line “Security”.
We will acknowledge your report, keep you informed while we fix it, and credit you if you want. Please do not access other people's data beyond what is needed to show the problem, do not run tests that degrade the service, and give us reasonable time to fix it before disclosing. We will not take legal action against good-faith research that follows these rules.
Questions about how your data is handled?
The privacy policy and data processing agreement go into the detail.