Owner/legal review required

Security

A concise description of Publishfy security controls and responsible disclosure.

Draft version: 2026-07-20 · This practical product draft is not a substitute for owner and qualified legal review.

Controlled beta. Capabilities depend on the in-product status shown for each connector. Provider review and external configuration may prevent connection or publishing.

Isolation

Workspace and brand authorization is resolved server-side. Customer identifiers supplied by the browser are not trusted to select another tenant.

Credentials

OAuth tokens are encrypted per brand with AES-256-GCM and versioned Worker secrets. Tokens, authorization codes, cookies, webhook signatures, and private media URLs are excluded from customer pages and logs.

Billing

Card data is collected and stored by Stripe-hosted Checkout and Portal. Publishfy provisions entitlements only from signature-verified, idempotently processed Stripe events.

Operations

Emergency switches fail closed, privileged mutations require platform-owner authorization, reason and idempotency, and production releases use review and validation gates.

Disclosure

Report a suspected vulnerability privately to security@publishfy.app. Do not access other customers, disrupt service, or publish sensitive evidence before coordinated review.

Contact

Use support@publishfy.app. Legal and privacy contact details remain subject to owner review before paid or public launch.