Security and control

Designed around explicit access and accountable actions.

ProfilePlusAI limits provider access to the features you choose, keeps sensitive credentials on the backend, and makes publishing an intentional owner action.

Protected connections

Google and Instagram connections use official OAuth flows. Provider tokens are stored encrypted and are not placed in the web or mobile bundle.

Owner-approved publishing

Drafting and previewing are separate from publishing. Unknown provider outcomes are surfaced for review rather than blindly replayed.

Scoped customer data

Business uploads, drafts, connected profiles, and publishing history are associated with the authenticated account and business.

Bounded provider work

External operations use documented timeouts, pagination limits, quotas, and degraded states instead of unmetered background requests.

Deletion controls

Owners can disconnect integrations and delete their account. Public instructions are available when app access is unavailable.

Responsible reporting

Report a suspected vulnerability privately to support@profileplusai.com. Do not include live credentials.

Security is an ongoing practice.

No internet service can promise absolute security. ProfilePlusAI reviews dependencies, access boundaries, provider behavior, and deployment controls as the product moves from pilot to broader availability.