Clear reporting · bounded claims

Security at Social Fanout

Security reports should reach a person, not disappear into a form. This page provides the current reporting path, responsible-testing boundaries, and safeguards documented for the hosted service.

Last reviewed: August 28, 2026

Report a vulnerability

Email hello@socialfanout.com with Security report in the subject. Include enough detail to reproduce and evaluate the concern:

Never email live secrets. Redact API keys, OAuth tokens, passwords, cookies, personal data, customer content, and raw provider credentials from the report and screenshots.
Email a security report

Automated security tooling can use the canonical security.txt record.

Responsible-testing boundaries

This page does not create a paid bug bounty, promise a response or remediation deadline, or authorize intrusive testing.

Documented safeguards

Scope and accountability

These controls reduce risk; they do not make any internet service unbreakable. This page is not a SOC 2, ISO 27001, PCI, or other certification claim. Social Fanout also depends on customer-owned accounts and upstream social providers, whose availability, permissions, and security controls remain separate.

For data handling and retention, read the Privacy Policy. For service limitations, read the Terms of Service. For fresh hosted-runtime checks, visit Service Status.