SECURITY

Your accounts, protected.

SocFlow connects to accounts you manage, so credential handling is treated as a first-class concern, not an afterthought.

Encrypted tokens
OAuth access and refresh tokens for every connected account are encrypted at rest (AES-GCM) and are never sent to your browser.
Hardened OAuth
Every connection flow is bound to a random, server-side, one-time-use state value tied to your account — never trusted from the client — plus PKCE, to close CSRF and token-injection attacks.
Per-workspace data isolation
Every request is authenticated and every read or write is scoped to your workspace. Membership and ownership are re-checked server-side before any mutation.
Locked-down headers
Every response sets HSTS, X-Frame-Options, X-Content-Type-Options, and a restrictive Content-Security-Policy to block clickjacking and MIME-sniffing attacks.

Found a security issue? Please report it to hello@socflow.io — we'll respond promptly.