Security & Infrastructure
Prabisha Consulting Limited • Digital Marketing Automation
Last Updated: July 28, 2026
At Prabisha Consulting Limited, safeguarding your marketing assets, brand workspaces, and social media integrations is our highest priority. Because our Digital Marketing Automation (DMA) platform handles sensitive API authorizations on your behalf, we implement strict, enterprise-grade security measures across our entire cloud infrastructure, application layer, and database.
Core Security Measures
All third-party access and refresh tokens (Meta, LinkedIn, Google) are encrypted at rest using AES-256-GCM. Tokens are decrypted in-memory only when actively executing an automated post, ensuring they are never exposed in database dumps or client-side responses.
All data in transit between your browser, our application servers, and external social media APIs is encrypted using TLS 1.3. We enforce HTTP Strict Transport Security (HSTS) across all platform domains.
User passwords are cryptographically hashed and salted using industry-standard bcrypt. We utilize secure, HTTP-only, SameSite cookies for session management to prevent Cross-Site Scripting (XSS) and token theft.
The platform utilizes strict RBAC to isolate Brand Workspaces. Only designated "Brand Admins" can manage billing, connect integrations, or invite users, ensuring standard users cannot accidentally alter sensitive configurations.
Our automated publishing engine runs on an isolated microservice backend. If the frontend experiences high load, the scheduling and queueing systems remain unaffected and secure inside a private subnet.
Databases are continuously backed up with Point-in-Time Recovery (PITR) enabled. Backups are heavily encrypted and stored redundantly across multiple geographic availability zones to ensure data durability.
Third-Party API Compliance
Because we integrate deeply with social networks, we strictly adhere to the developer terms and security guidelines mandated by our partners:
Least Privilege Access: We request only the specific OAuth scopes required to publish content and read analytics. We never request permission to alter your personal passwords or delete your social accounts.
Data Minimization: We fetch and cache comments/analytics temporarily to display them in your dashboard. We do not permanently store social data longer than necessary for your active workflows.
Provider Audits: Our application undergoes periodic security reviews and compliance audits enforced by Google, Meta, and LinkedIn to maintain our verified developer status.
Incident Response & Breach Protocol
Your Role in Security
Security is a shared responsibility. To keep your brand workspaces secure, we strongly advise you to:
- Never share your login credentials with team members (invite them to your workspace instead).
- Ensure the devices you use to access the platform are free of malware.
- Regularly audit the users inside your Brand Workspaces and remove access for departing employees.
Report a Security Concern
If you have discovered a vulnerability or suspect your account has been compromised, please contact our security team immediately.
Report Security Issue