Skip to content
Outbox Loop

Security

Version 2026-09-01 · Last updated 1 September 2026

How we protect your data, and how to tell us if we got something wrong.

Secrets

Instagram access tokens and AI provider keys are encrypted with a data key that is itself wrapped by a key managed in Google Cloud KMS. Neither is ever returned to a browser, and both are decrypted only inside a server process for a single call.

We never receive your Instagram password.

Access control

Every workspace is isolated. Database rules deny access by default and are enforced independently of the application, so a bug in one layer does not become a data leak.

Roles limit what team members can do, and privileged actions are re-checked on the server rather than trusted from the browser. Sensitive actions are recorded in an audit log.

We do not offer casual 'log in as customer' support impersonation.

Reporting a vulnerability

Email support@colormetriclabs.com with details and steps to reproduce. We will acknowledge within 3 working days.

Please do not access other users' data, degrade the service, or publish details before we have had a chance to fix the issue. We will not pursue good-faith research that follows these rules.