Security
Last updated: 6 June 2026
Security is foundational to a tool that touches your audience. Here is how we protect your data and accounts.
Data in transit and at rest
All traffic is encrypted in transit (TLS). Secrets and credentials are stored encrypted, and generated media lives in access-controlled object storage.
We don't hold your platform tokens
Social publishing is handled through our integration partner, Zernio, which holds the platform OAuth tokens. Threadovo publishes by account reference and never stores your Instagram, TikTok, X, or other platform credentials.
Tenant isolation
Every workspace is isolated. Queries are scoped to your workspace, and content and accounts from one tenant are never accessible to another.
Payments
Card data is handled entirely by PCI-compliant processors (Paystack and Stripe). We receive only payment status and references — never raw card numbers.
Authentication
Passwords are hashed with a modern algorithm, sessions are short-lived and signed, and sensitive endpoints are rate-limited to slow brute-force attempts. Optional social sign-in uses verified provider identities.
Reporting a vulnerability
If you believe you’ve found a security issue, please email security@threadovo.app with details. We appreciate responsible disclosure and will respond promptly.