Provider authorization
AutoPostMD uses provider authorization flows instead of asking for your social-platform password.
Our security approach is built around user-directed publishing, limited access, and clear control over connected accounts.
AutoPostMD is not marketed as HIPAA compliant at launch. Do not upload protected health information or medical records.
AutoPostMD uses provider authorization flows instead of asking for your social-platform password.
Production website and callback traffic is sent over HTTPS. Sensitive credentials must not appear in client-side code.
Application services, databases, queues, storage, and deployment access are limited to the systems and people needed to operate the service.
Access tokens, authorization codes, uploaded content, and sensitive profile data should not be written to routine logs.
Uploaded media is intended to remain private except for controlled processing and the destinations you direct AutoPostMD to publish to.
You can review destinations, disconnect accounts, revoke provider access, and request deletion.
Security also depends on the choices you make. Use a unique password, protect access to your email and devices, confirm the correct destination before publishing, remove former team access, and disconnect accounts you no longer use.
If you believe an AutoPostMD account or connection has been compromised, disconnect the affected provider when possible and contact support@autopostmd.com. Include the account email, affected platform, approximate time, and a description of what you observed. Do not email passwords, access tokens, medical records, or patient information.
Security, privacy, and deletion are connected. The Privacy Policy explains information practices, the Platform Connections page explains authorization, and the Data Deletion page explains how to request removal.