

Security
Last updated: March 2026
TLS Encryption
All data in transit
Encrypted Storage
Data at rest
Access Controls
Least-privilege
Bug Bounty
Responsible disclosure
Security Headers
VerifiedAll 5 critical headers active: X-Frame-Options, X-Content-Type, X-XSS-Protection, HSTS, and Content-Security-Policy.
XSS & CSRF Protection
VerifiedAll inputs sanitized and escaped. CSRF tokens enforced on all state-changing requests.
Rate Limiting
Verified100 requests/minute per IP on the API. Frontend routes protected against abuse at the edge.
No Secrets Exposed
VerifiedAPI keys and environment variables never leaked to the client. .env files blocked from public access.
Secure Infrastructure
VerifiedHosted on Railway and Vercel with TLS 1.3, AES-256 encryption at rest, and SSL certificates auto-renewed.
Data Privacy
CompliantGDPR and CCPA compliant. No personal data sold or shared. Minimal data collection policy.
Our platform is hosted on industry-standard cloud infrastructure with the following protections in place:
Payments are processed entirely by NowPayments. We never receive, transmit, or store private keys, wallet addresses, or transaction details. All payment data flows directly between you and NowPayments over their encrypted infrastructure.
We receive only a transaction confirmation (order ID, status, amount) after a successful payment.
Every dataset download is logged with the timestamp, IP address, and authenticated user account. This serves two purposes:
Download logs are retained for 12 months. They are never shared with third parties except as required for payment disputes or by law. See our Privacy Policy for details.
Each user can only access datasets they have purchased. Access tokens are scoped per user and per dataset — there is no way to access another user's purchases through the API. Subscription access is revoked immediately upon cancellation or refund.
We take security vulnerabilities seriously. If you discover a security issue in our platform, please report it to us privately before disclosing it publicly.
To report a vulnerability: email info@socialintel.io with a description of the issue and steps to reproduce it. We will acknowledge your report within 48 hours and aim to resolve confirmed issues within 14 days.
We ask that you do not access, modify, or delete any user data beyond what is necessary to demonstrate the vulnerability. We will not take legal action against researchers who follow these guidelines.
In the event of a security incident affecting user data, we will notify affected users by email within 72 hours of becoming aware of the breach. Notifications will include the nature of the incident, data involved, and steps we have taken to contain it.
For security-related enquiries or to report a vulnerability: info@socialintel.io
For general privacy questions, see our Privacy Policy.