Security
Secure defaults, least privilege, and no secrets in logs.
Promote HQ is built for teams that need to run autonomous publishing safely and prove what happened.
Tenant isolation
Every tenant-owned row carries a workspace identifier and is protected by Postgres Row Level Security. Permissions are enforced server-side as well as in the interface, so a crafted request cannot escape its workspace.
Secrets
- OAuth tokens and customer AI keys are encrypted with AES-256-GCM before persistence.
- Secret keys are never exposed to the browser.
- Access tokens, refresh tokens, payment details and AI keys are redacted from logs and errors.
- Customer AI keys can be revoked immediately.
Request integrity
- Webhook signature verification and replay protection with idempotent event handling.
- OAuth state and PKCE where the provider requires it.
- Secure cookies, CSRF protection for state-changing routes, input validation and output encoding.
- Rate limiting on authentication, API and generation routes.
- Strict security headers and a restrictive content security policy.
Operations
- Audit logging for privileged and automated actions.
- Account export and deletion workflows, plus connector revocation.
- Data-retention configuration and PII-aware logging.
- Dependency scanning and secret scanning in CI.
Reporting a vulnerability
Please contact security@promote-hq.app. We aim to acknowledge reports within two business days.