TLS everywhere
All dashboard, API, and webhook traffic is encrypted in transit with modern cipher suites.
Agencies and publishers connect production systems. We design for least privilege, encrypted transport, and clear audit trails from day one.
Controls
Security is a moving target—these practices describe our current baseline and roadmap commitments.
All dashboard, API, and webhook traffic is encrypted in transit with modern cipher suites.
CMS credentials are stored encrypted and can be rotated or revoked per property without downtime.
Invite teammates with the least privilege required—viewer, editor, approver, or admin.
Publishing and approval events are retained for investigations and compliance exports.
Client data never bleeds across workspaces; background jobs are keyed by tenant.
Failed publishes backoff automatically to avoid hammering fragile CMS endpoints.
Enterprise plans can integrate SAML/OIDC providers—contact us for the current rollout timeline.
Primary regions are documented during onboarding. Enterprise customers may request dedicated deployment options.
Email security@blogpostscheduler.com with reproduction steps. We acknowledge critical reports within 48 business hours.
We provide standard responses for SOC2-style reviews and can join security calls for large deployments.