Security & Infrastructure

    Prabisha Consulting Limited • Digital Marketing Automation

    Last Updated: July 28, 2026

    At Prabisha Consulting Limited, safeguarding your marketing assets, brand workspaces, and social media integrations is our highest priority. Because our Digital Marketing Automation (DMA) platform handles sensitive API authorizations on your behalf, we implement strict, enterprise-grade security measures across our entire cloud infrastructure, application layer, and database.

    Core Security Measures

    OAuth Token Encryption

    All third-party access and refresh tokens (Meta, LinkedIn, Google) are encrypted at rest using AES-256-GCM. Tokens are decrypted in-memory only when actively executing an automated post, ensuring they are never exposed in database dumps or client-side responses.

    Transport Security (TLS)

    All data in transit between your browser, our application servers, and external social media APIs is encrypted using TLS 1.3. We enforce HTTP Strict Transport Security (HSTS) across all platform domains.

    Authentication Identity

    User passwords are cryptographically hashed and salted using industry-standard bcrypt. We utilize secure, HTTP-only, SameSite cookies for session management to prevent Cross-Site Scripting (XSS) and token theft.

    Role-Based Access Control

    The platform utilizes strict RBAC to isolate Brand Workspaces. Only designated "Brand Admins" can manage billing, connect integrations, or invite users, ensuring standard users cannot accidentally alter sensitive configurations.

    Microservice Isolation

    Our automated publishing engine runs on an isolated microservice backend. If the frontend experiences high load, the scheduling and queueing systems remain unaffected and secure inside a private subnet.

    Automated Backups

    Databases are continuously backed up with Point-in-Time Recovery (PITR) enabled. Backups are heavily encrypted and stored redundantly across multiple geographic availability zones to ensure data durability.

    Third-Party API Compliance

    Because we integrate deeply with social networks, we strictly adhere to the developer terms and security guidelines mandated by our partners:

    • Least Privilege Access: We request only the specific OAuth scopes required to publish content and read analytics. We never request permission to alter your personal passwords or delete your social accounts.

    • Data Minimization: We fetch and cache comments/analytics temporarily to display them in your dashboard. We do not permanently store social data longer than necessary for your active workflows.

    • Provider Audits: Our application undergoes periodic security reviews and compliance audits enforced by Google, Meta, and LinkedIn to maintain our verified developer status.

    Incident Response & Breach Protocol

    Immediate ContainmentWe instantly revoke compromised tokens and isolate affected services.
    72-Hour NotificationAffected users and legal authorities are notified per GDPR requirements.
    Transparent ResolutionWe provide a post-mortem report and deploy permanent mitigations.

    Your Role in Security

    Security is a shared responsibility. To keep your brand workspaces secure, we strongly advise you to:

    • Never share your login credentials with team members (invite them to your workspace instead).
    • Ensure the devices you use to access the platform are free of malware.
    • Regularly audit the users inside your Brand Workspaces and remove access for departing employees.

    Report a Security Concern

    If you have discovered a vulnerability or suspect your account has been compromised, please contact our security team immediately.

    Report Security Issue