Trust center

Security at AutoPostMD

Our security approach is built around user-directed publishing, limited access, and clear control over connected accounts.

Effective and last updated: September 15, 2026

AutoPostMD is not marketed as HIPAA compliant at launch. Do not upload protected health information or medical records.

Provider authorization

AutoPostMD uses provider authorization flows instead of asking for your social-platform password.

Protected transport

Production website and callback traffic is sent over HTTPS. Sensitive credentials must not appear in client-side code.

Controlled infrastructure

Application services, databases, queues, storage, and deployment access are limited to the systems and people needed to operate the service.

Restricted logging

Access tokens, authorization codes, uploaded content, and sensitive profile data should not be written to routine logs.

Private media access

Uploaded media is intended to remain private except for controlled processing and the destinations you direct AutoPostMD to publish to.

User control

You can review destinations, disconnect accounts, revoke provider access, and request deletion.

Shared responsibility

Security also depends on the choices you make. Use a unique password, protect access to your email and devices, confirm the correct destination before publishing, remove former team access, and disconnect accounts you no longer use.

Report a security concern

If you believe an AutoPostMD account or connection has been compromised, disconnect the affected provider when possible and contact support@autopostmd.com. Include the account email, affected platform, approximate time, and a description of what you observed. Do not email passwords, access tokens, medical records, or patient information.

Privacy and deletion

Security, privacy, and deletion are connected. The Privacy Policy explains information practices, the Platform Connections page explains authorization, and the Data Deletion page explains how to request removal.