

We use essential cookies to keep you signed in and improve your experience. Cookie Policy
Security
Last updated: May 2026
TLS 1.3
All data in transit
AES-256
Encrypted at rest
Least-Privilege
Role-based access
Bug Bounty
Responsible disclosure
PostgreSQL
Connection pooling
CORS Restricted
Own domains only
Email Verification Enforcement
VerifiedEmail verification is sent automatically on registration and is required before accessing sensitive account features. Login is blocked until the email is verified when enforcement is enabled.
2FA Requires Verified Email
VerifiedTwo-factor authentication can only be enabled after email verification. This prevents account takeover via 2FA lockout on unverified accounts.
Unverified Account Cleanup
AutomatedAccounts that remain unverified beyond the configured TTL (default 30 days) are automatically and permanently deleted by the background worker. This limits exposure from abandoned registrations.
Security Headers
VerifiedAll critical headers active: X-Frame-Options (DENY), X-Content-Type-Options (nosniff), HSTS (2yr preload), Referrer-Policy, Permissions-Policy (camera/mic/geo blocked), and Content-Security-Policy.
XSS & CSRF Protection
VerifiedAll inputs sanitized and escaped server-side. CSRF tokens enforced on all state-changing requests. X-XSS-Protection header set.
Rate Limiting by Tier
VerifiedTiered rate limits: Free (1,000 req/day), Pro (10,000 req/day), Max (100,000 req/day). Burst limits: Free 10/s, Pro 50/s, Max 200/s. Frontend routes protected at the edge.
No Secrets Exposed
VerifiedAPI keys hashed server-side (shown once at creation). Environment variables never leaked to client. .env files blocked from public access via redirect.
JWT Authentication
VerifiedJWT-based session tokens with configurable expiry. Bearer token or X-API-Key accepted per request. Passwords hashed with bcrypt — never stored in plaintext.
CORS & SSRF Protection
VerifiedCORS restricted to socialintel.io, www.socialintel.io, and api.socialintel.io. SSRF protection blocks requests to internal networks (169.254.x.x, 10.x.x.x, 127.0.0.1, etc.).
Secure Infrastructure
VerifiedHosted on Railway and Vercel with TLS 1.3, AES-256 encryption at rest, SSL certs auto-renewed. PostgreSQL with connection pooling, S3 for dataset storage.
Error Monitoring
VerifiedSentry integrated for real-time error tracking. No sensitive data (passwords, tokens, PII) included in error reports.
Data Privacy
CompliantGDPR and CCPA compliant. No personal data sold or shared. Minimal data collection policy. Data deletion available under GDPR Article 17.
Our platform is hosted on industry-standard cloud infrastructure with the following protections in place:
Payments are processed entirely by PayPal. We never receive, transmit, or store card details or banking information. All payment data flows directly between you and PayPal over their encrypted infrastructure.
We receive only a transaction confirmation (order ID, status, amount) after a successful payment.
Every dataset download is logged with the timestamp, IP address, and authenticated user account. This serves two purposes:
Download logs are retained for 12 months. They are never shared with third parties except as required for payment disputes or by law. See our Privacy Policy for details.
Each user can only access datasets they have purchased. Access tokens are scoped per user and per dataset — there is no way to access another user's purchases through the API. Subscription access is revoked immediately upon cancellation or refund.
We take security vulnerabilities seriously. If you discover a security issue in our platform, please report it to us privately before disclosing it publicly.
To report a vulnerability: email info@socialintel.io with a description of the issue and steps to reproduce it. We will acknowledge your report within 48 hours and aim to resolve confirmed issues within 14 days.
We ask that you do not access, modify, or delete any user data beyond what is necessary to demonstrate the vulnerability. We will not take legal action against researchers who follow these guidelines.
In the event of a security incident affecting user data, we will notify affected users by email within 72 hours of becoming aware of the breach. Notifications will include the nature of the incident, data involved, and steps we have taken to contain it.
For security-related enquiries or to report a vulnerability: info@socialintel.io
For privacy-related requests (data access, deletion, correction): privacy@socialintel.io
For general privacy questions, see our Privacy Policy or Data Deletion page.