Authentication & access
JWT-based application sessions, secure production cookies, Google OAuth support, workspace-aware authorization, and protected dashboard routes.
Trust
ViralFlow AI combines application-layer safeguards, managed infrastructure, encrypted secrets, production observability, and operational controls to protect content workflows and connected-platform access.
Security controls
Security is implemented as a collection of controls across identity, application traffic, connected platforms, storage, deployments, and operations.
JWT-based application sessions, secure production cookies, Google OAuth support, workspace-aware authorization, and protected dashboard routes.
Connected-platform access and refresh credentials are treated as secrets and encrypted before persisted application storage.
Production traffic uses HTTPS with strict transport security, restrictive framing policies, content-type protections, and origin validation for protected API mutations.
Generated media can be stored in Cloudflare R2 with dedicated temporary and production storage paths rather than relying solely on ephemeral application disks.
Production relational data and queue state run in dedicated managed services and are accessed using environment-specific credentials.
Sentry error monitoring, structured runtime logging, health endpoints, worker heartbeats, and operational events support incident detection and diagnosis.
Production deployments use versioned source control, Prisma migrations, environment validation, health checks, and standalone Next.js runtime packaging.
The platform includes circuit breakers, safe-mode concepts, rollout health policies, recovery controls, and audit-oriented operational workflows.
Shared responsibility
Use unique accounts, protect the Google/TikTok/Meta accounts you connect, restrict workspace access to people who need it, and review automated publishing policies before enabling production execution.
Immediately revoke platform access and contact us if you believe a ViralFlow AI account or connected-platform credential has been compromised.
Report a concern
Please send enough information for us to reproduce and evaluate the issue, while avoiding unnecessary access to data belonging to other users.
Contact security