Security

Security at Someo

Your connected accounts and lead data are among the most sensitive things we handle. Here’s exactly how we protect them.

Official API access only

Someo connects to social platforms using their official OAuth 2.0 APIs. We never use scraping, browser automation, fake accounts, unofficial clients, or third-party graph tools. Every action taken on a connected account is an authorised API call.

  • Meta Graph API for Instagram and Facebook
  • WhatsApp Cloud API for WhatsApp messaging
  • Platform-issued OAuth tokens — no password sharing
  • Tokens scoped to minimum required permissions

Encrypted token storage

OAuth tokens that grant access to your social accounts are stored encrypted at rest using AES-256 encryption. They are never logged, never exposed to front-end code, and never shared with third parties.

  • AES-256 encryption at rest
  • Tokens never appear in logs or API responses
  • Per-account token isolation
  • Revoke access any time from your Settings page

Database and infrastructure

Your data is stored in a hosted Postgres database with row-level security policies. All database traffic is encrypted in transit using TLS. Backups are encrypted and retained for disaster recovery.

  • Row-level security policies on all sensitive tables
  • TLS encryption for all data in transit
  • Encrypted database backups
  • Isolated per-workspace data access

Access controls

Each workspace has its own permission boundary. Members can only access the workspaces they have been explicitly invited to. Only you can manage billing, connected accounts, and workspace members for your workspace.

  • Workspace-scoped data isolation
  • Invite-only workspace access
  • Authentication via Clerk with MFA support
  • No cross-workspace data access

Platform policy compliance

Every integration Someo offers complies with the platform's developer policies and terms of service. We do not enable automation that violates platform rules — no fake engagement, no mass following, no unsolicited DMs to strangers.

  • Automation only responds to genuine user actions (comments)
  • Respects platform rate limits and messaging windows
  • No auto-follow, auto-like, or mass cold outreach
  • All actions triggered by explicit user engagement

Monitoring and incident response

Our infrastructure is monitored around the clock. If a security incident occurs that affects your data, we'll notify you in accordance with our Privacy Policy and applicable law within the required timeframe.

  • 24/7 infrastructure monitoring
  • Automated anomaly detection on API usage
  • Incident disclosure within 72 hours where required
  • Audit logs for all account actions

Our commitments to you

  • We will never sell, rent, or share your data or your followers' data
  • We will never impersonate you on any platform
  • We will never send messages on your behalf outside of your configured campaigns
  • We will never store your platform password
  • We will never use your account to test features without notice

Report a security issue

If you discover a vulnerability in Someo, please report it responsibly. Do not exploit the issue or share it publicly before we have had a chance to address it. Email your findings to support@someo.app with the subject line: “Security Vulnerability Report”. We take all reports seriously and will respond within 3 business days.