Security
Security at SocialSpider AI
Last reviewed January 2026
Security is foundational to everything we build. Your brand data, social credentials, and content are held to the highest standards of protection.
At a glance:
- TLS 1.3 — encryption in transit
- AES-256 — encryption at rest
- SOC 2 Type II — in progress
- OAuth 2.0 only — no password storage
Data encryption
All data transmitted between your browser and our servers is encrypted using TLS 1.3. Data stored in our databases is encrypted at rest using AES-256. Social media OAuth tokens are stored in an encrypted secrets vault with strict access controls.
Authentication
We support multi-factor authentication (MFA) on all accounts. We strongly recommend enabling MFA in your account settings. We use industry-standard OAuth 2.0 for connecting social media accounts — we never request or store your social media passwords.
Infrastructure
SocialSpider AI runs on AWS infrastructure in multiple availability zones for high availability. Our infrastructure is managed using infrastructure-as-code with automated security scanning. Access to production systems is restricted to authorised engineers with audit logging on all actions.
Vulnerability disclosure
We operate a responsible disclosure programme. If you discover a security vulnerability, please report it to [email protected]. We commit to acknowledging reports within 24 hours and resolving critical issues within 72 hours.
Penetration testing
We conduct annual penetration tests with independent third-party security firms and address findings before they can be exploited.
Incident response
We maintain a documented incident response plan. In the event of a data breach affecting your account, we will notify you within 72 hours in compliance with applicable data protection regulations.
Contact
Security questions or reports: [email protected]