Security & Trust
Last updated: September 29, 2026
This page describes the controls that protect your data in AlgoMuse today. It lists only what is in place now, not plans. AlgoMuse does not currently hold third-party security certifications or audit reports such as SOC 2 or ISO 27001.
Encryption
HTTPS for every connection to us
The website, the app and the API are served only over TLS, with certificates from Let's Encrypt. Plain HTTP is redirected, and browsers are told to use HTTPS only (HSTS).
Credentials encrypted in the database
Access and refresh tokens for the accounts you connect, integration and webhook secrets, stored API credentials and two-factor secrets are encrypted with AES-256-GCM before they are written to the database.
Hashed passwords
Passwords are hashed with scrypt and never stored in readable form.
Accounts and access
Two-factor authentication
Anyone can turn on two-factor sign-in with an authenticator app (TOTP), with 10 one-time backup codes. It is optional.
Role-based access
Each workspace has owner, admin, member and viewer roles, and the server checks the permission behind every request. Billing and deleting a workspace are reserved for the owner.
Sessions you control
Sessions last 7 days while in use and end 30 days after sign-in at most. You can see your active sessions and sign any of them out, and changing or resetting your password signs out your other sessions.
Hashed API keys
API keys are stored only as keyed hashes (HMAC-SHA256), so the full key is shown once, when it is created. Afterwards you see its prefix and last four characters. Keys can be limited to specific IP addresses or origins.
Connected accounts
Social, ad and commerce accounts connect through each platform's own authorization flow; Bluesky uses an app password you create and can revoke in Bluesky. We never ask for your main social media password, and disconnecting an account removes our access token.
Application protection
Rate limiting
Requests are rate limited per IP address, with tighter limits on sign-in, sign-up and password reset, and repeated failed sign-ins to one account are throttled.
Browser protections
Forms and API calls from the app are protected against cross-site request forgery, and pages send security headers including a Content Security Policy.
Workspace separation
Every record belongs to a workspace, queries are scoped to the workspace you are working in, and an automated check in our build flags new queries that are not.
Tamper-evident audit log
Changes made in a workspace and actions taken by our administrators are recorded in an audit log. Each entry carries a SHA-256 hash of the one before it, so an altered or missing entry can be detected. Entries are kept for 365 days.
Infrastructure and recovery
Infrastructure we operate
The application, database, cache and file storage run on a Kubernetes cluster we operate ourselves rather than on a public cloud, with Cloudflare in front of public traffic. The hosting location is available on request.
Nightly backups
The database is backed up every night, and each backup is kept for 14 days.
Checks on every change
Code changes go through review and automated checks before release: dependency vulnerability audits, secret scanning and static analysis on each change, container image scanning before deployment, and a weekly vulnerability scan.
Incident response
We follow a documented incident-response runbook, and we will tell affected customers about incidents involving their data as the law requires.
AI and your data
Only what the request needs
When you use an AI feature, the content for that request is sent to the AI provider handling it (listed on our Subprocessors page). Embeddings and search over your workspace data run on our own infrastructure.
No model training on your content
AlgoMuse does not train AI models on your content. Brand memory and other personalization stay in your workspace.
Report a vulnerability
If you believe you have found a security issue in AlgoMuse, email [email protected] rather than opening a public issue. Please include:
- what the issue is and what an attacker could do with it,
- steps to reproduce it, with a proof of concept if you have one,
- the URLs, endpoints or accounts involved.
We aim to acknowledge reports within a few business days and will keep you updated while we fix the issue. Please give us reasonable time to fix it before disclosing it, only test against accounts you own, and do not access other people's data or degrade the service.
In scope: algomuse.io and its subdomains, including the app and the API. Out of scope: third-party services we use, social engineering, physical attacks and denial of service. We do not run a paid bug bounty. Our contact details are also published at /.well-known/security.txt.
Security reviews and documents
Reviewing AlgoMuse as a vendor? The Subprocessors page lists every third party that processes customer data, the Privacy Policy explains what we collect and why, and you can request a Data Processing Addendum. For security questionnaires or other questions, email [email protected].