SignalFlow EngineSignalFlow Engine
PrivacyTermsContact

Security

Last updated: July 15, 2026

This page describes SignalFlow Engine’s general security practices for our social publishing platform. It is not a certification statement and does not claim that any system is completely secure.

1. Secure authentication

SignalFlow uses a managed authentication provider (Supabase) to support account registration, sign-in, and session handling. Users authenticate with credentials managed through that provider. We design account flows to keep sessions associated with the authenticated user.

2. Access control

Application features are designed so that authenticated users can access their own workspace data and actions appropriate to their account. Administrative areas, where present, are restricted to authorised operators. We aim to limit access to production systems and customer data to people who need it to operate the Service.

3. OAuth-based social integrations

Social account connections for platforms such as LinkedIn, X / Twitter, Facebook, Instagram, YouTube, and TikTok use OAuth (or equivalent platform authorisation flows). SignalFlow requests permissions needed to connect accounts and publish content you instruct us to publish. Connection flows use short-lived state protections designed to reduce CSRF risk during account linking.

4. Credential handling

OAuth access tokens and refresh tokens for connected social accounts are stored so the Service can perform authorised publishing and connection checks on your behalf. Payment card details for subscriptions are processed by Stripe and are not stored by SignalFlow as full card numbers. Users should never send passwords or tokens to support by email.

5. Environment separation and production secrets

Application secrets and third-party credentials are kept separate from application source code using environment configuration. Access to production secrets is restricted to authorised operational use. We do not publish production credentials in client-side code.

6. Your responsibility for account security

You can help protect your account by:

  • Using a strong, unique password
  • Keeping your login credentials confidential
  • Signing out of shared devices
  • Reviewing connected apps on social platforms periodically
  • Disconnecting integrations you no longer need
  • Contacting us promptly if you suspect unauthorised access

7. Responsible vulnerability reporting

If you discover a potential security issue, please email support@signalflowengine.com with:

  • A clear description of the issue
  • Steps to reproduce, where possible
  • Potential impact, if known
  • Your contact details for follow-up

Please act in good faith: do not access more data than needed to demonstrate the issue, do not disrupt the Service, and do not publicly disclose the vulnerability before we have had a reasonable opportunity to investigate and address it.

8. Third-party platform dependencies

SignalFlow depends on third-party services for authentication, database storage, billing, email delivery, hosting, and social publishing APIs. Those providers maintain their own security practices. Availability and security of third-party platforms can affect SignalFlow features that rely on them.

9. No absolute security guarantee

We work to protect the Service with reasonable safeguards, but no online service can guarantee complete security. Transmission of information over the internet and storage of electronic data involve residual risk. For privacy practices, see our Privacy Policy. For support, visit Contact.

Report a vulnerability

Email support@signalflowengine.com with the subject line “Security Report.” See responsible reporting guidance below.

PrivacyTermsCookiesData DeletionAcceptable UseContactSecurity

© 2026 SignalFlow Engine. Back to home