Collecting now · 135 tracked sourcesKuwait · +965 2241 5093Status
Security & Trust

Your data is our responsibility

Social Hub handles competitive intelligence, customer conversations, and financial transactions. Security is built into every layer: from encryption to access controls to infrastructure.

AES-256

Encryption standard

TLS 1.2+

Transport security

Germany

Server location

72 hours

Breach notification

Security Architecture

Four layers of protection

Encryption

  • TLS 1.2+ on all connections, HTTPS enforced everywhere
  • AES-256 encryption for data at rest in MySQL
  • OAuth tokens encrypted with AES-256-CBC application keys
  • End-to-end encrypted API calls to Meta, AI providers, Apify, MyFatoorah

Infrastructure

  • Dedicated servers at Hetzner, Germany
  • Ubuntu 24.04 LTS with automated security patches
  • UFW firewall with strict allow-list rules
  • SSH key-only authentication, password auth disabled
  • Nginx reverse proxy with rate limiting
  • Automated daily encrypted backups with off-site copies

Application Security

  • CSRF protection on all state-changing requests
  • SQL injection prevention via parameterized queries only
  • XSS prevention through Vue.js auto-escaping + server-side sanitization
  • Rate limiting on auth endpoints, API routes, and forms
  • Server-side file upload validation, MIME type, extension, and size

Access Controls

  • Role-based access, Admin, Team Owner, Agent, Viewer
  • Multi-tenancy isolation, every query scoped to current team
  • Branch-level scoping, agents restricted to specific departments
  • Laravel Sanctum token-based API authentication
  • Configurable session lifetimes with secure cookie attributes
Third-Party Security

Every integration vetted

Meta (Facebook / Instagram)

OAuth 2.0 with scoped permissions. Tokens auto-refreshed and revoked on disconnect. Webhook signatures verified on every callback.

WhatsApp Business API

Encrypted messaging through Meta's Cloud API. No message content stored beyond delivery.

AI Engine

API-key authenticated. No customer data used for model training. Conversations not retained beyond processing.

MyFatoorah

PCI-DSS compliant payment gateway. Credit card numbers never touch our servers: all payment processing on MyFatoorah infrastructure.

Apify

Public data collection platform. We run custom-built actors for social media, retail, and restaurant data collection. API-key authenticated with per-run isolation.

Data Retention

We keep only what's needed

Data typeRetention period
Account dataActive subscription + 30 days after closure
OAuth tokensRevoked within 24 hours of disconnect
Conversation dataPer team settings, deletable by admins
Application logsRotated daily, retained 14 days
Security audit logsRetained 90 days

Incident Response

  1. 1Detection via automated monitoring and alerting
  2. 2Containment and assessment within 4 hours
  3. 3Customer notification within 72 hours for confirmed breaches
  4. 4Root cause analysis and remediation
  5. 5Post-incident review and preventive measures

Report a Vulnerability

If you discover a security vulnerability in Social Hub, please report it to us. We take all reports seriously and will acknowledge receipt within 48 hours.

intel@majestic-kw.com

Last updated: June 2026