Security
Data Security
Effective date: June 28, 2026
Private-by-Design
The public website does not display user channel portfolios, subscribers, watch hours, revenue, or analytics data. Connected channel data should be stored under the authenticated user account.
Read-Only Access
The YouTube integration should use read-only scopes wherever possible. The product is designed for monitoring and reporting, not changing channel content.
Recommended Production Controls
- Use HTTPS on all pages.
- Store OAuth tokens encrypted at rest.
- Restrict database rows by user ID/workspace ID.
- Use audit logs for sensitive account actions.
- Enable least-privilege admin access.
Contact
Questions may be sent to [email protected].