Connected social accounts use platform authorization instead of asking users to disclose social passwords.
Sensitive integration tokens are treated as secrets and protected using application-level controls.
Organization and brand access is enforced through authenticated roles and server-side permission checks.
Important customer and administrator actions are logged to support troubleshooting and accountability.
1. Security controls
- HTTPS/TLS for data in transit on production domains.
- Strong password hashing for SociGaps user passwords.
- Encrypted handling of sensitive integration credentials at rest where implemented.
- Role-based access controls for customer workspaces and Super Admin functions.
- CSRF protection and request validation for sensitive web actions.
- Rate limiting and security headers to reduce common web risks.
- Audit logs for relevant administrative and product events.
- Separation between public corporate pages and authenticated application areas.
2. Social account credentials
SociGaps does not ask you to provide a Facebook or Instagram password. Meta integrations use Meta's authorization process. You should never enter a Facebook/Instagram password into a SociGaps form or send one to SociGaps support.
3. Responsible disclosure
If you believe you have found a security vulnerability, email sm@qort.com with the subject “SociGaps Security Report”. Please include enough information to reproduce the issue without accessing or modifying data that does not belong to you.
4. Security incident handling
We investigate credible security incidents, take reasonable steps to contain and remediate them, preserve relevant evidence, and provide notices where required by applicable law or contract.
5. No certification claim
Unless expressly stated on this page in the future, SociGaps does not claim SOC 2, ISO 27001, PCI DSS or other independent security certification. We prefer to state implemented controls accurately rather than imply a certification that has not been completed.