Skip to content

Trust center

Security and operational readiness for Instagram workspace infrastructure.

Apionics is early access. Current controls are live and documented. Enterprise documentation is in progress.

Credential protectionEncrypted tokensAudit logsData deletion

Credential handling

Passwords are hashed, workspace credentials are protected, and platform credentials are encrypted before storage.

Transport security

Apionics is served over HTTPS and uses signed session cookies. Public examples keep real workspace credentials out of the browser.

Auditability

Login, account changes, access-control events, revocation, and recovery attempts are written to audit logs.

Security posture

Workspace credential protectionLive
Token encryptionLive
Audit logsLive
Data deletion processLive
Subprocessors registerPlanned
DPA documentationPlanned
SOC 2 readiness reviewFuture review

Platform compliance

Apionics is built around official permission paths, reviewable access, account-level controls, and auditable workspace actions.

Official permissionsReviewable accessAccount-level controlsAuditable actions

Permission boundaries

  • Official permission flows only
  • Password sharing is not required
  • Account access stays permission-based
  • No background publishing outside user actions

Public examples use placeholder credentials. Real credentials belong only in authenticated workspace and server-side flows.

Current status

Available today, with enterprise documents in progress.

Early access

Available today

  • Instagram platform status is separated from planned platform coverage
  • Workspace access credentials can be rotated or revoked from the workspace
  • Platform tokens and private credentials are encrypted before storage
  • Workspace data deletion process is available

In progress / planned

  • Formal DPA
  • Subprocessors register
  • Security questionnaire package
  • Documented incident response policy

Live controls

  • Instagram platform status is separated from planned platform coverage
  • Workspace access credentials can be rotated or revoked from the workspace
  • Platform tokens and private credentials are encrypted before storage
  • Workspace data deletion process is available

Operational controls

  • Audit logs are visible inside the workspace
  • Token expiry warnings are surfaced in the dashboard
  • System status page separates live platform coverage from rollout plans
  • Recovery-key password reset is available for owner access

Contact & escalation

Security reports and privacy/data requests are routed through dedicated addresses. Please include affected account, workspace, endpoint, and reproduction details when relevant.

Security reports

[email protected]

Responsible disclosure and incident coordination.

Privacy / Data

[email protected]

Data handling questions and deletion requests.

Security and privacy contacts published