[ SECURITY ]
You are handing us
the keys. Here is how
we hold them.
Connecting your social accounts to any tool is an act of trust. This page says exactly what that trust rests on at Echoia, in mechanisms rather than adjectives, including the section most security pages leave out: what we do not claim.
We never see your passwords
Connecting a social account happens on the platform's own login page, through OAuth. You type your password at Instagram, TikTok or LinkedIn, never at Echoia, and the platform hands us an access token limited to the permissions shown on its consent screen. The one exception is Bluesky, which works with app passwords by design: you create a dedicated app password in Bluesky's settings, it is distinct from your real one, and you can revoke it there at any time.
Tokens are encrypted at rest
Access tokens are the keys to your accounts, so they are stored encrypted with AES-256-GCM, and decrypted only at the moment an API call needs them. Login sessions and traffic run over TLS. Your own Echoia password, if you use one instead of Google sign-in, is stored as a salted hash: we could not read it if we wanted to.
Revoking access takes one click, on either side
Disconnect an account in Echoia and its tokens are gone. Revoke Echoia from the platform's security settings and our token stops working at once, whatever the state of your Echoia account. You are never locked in by the connection itself.
Your data lives in the European Union
The production database and application hosting run in the EU (Frankfurt), analytics are EU-hosted, and every subprocessor is named in the privacy policy, with what each one sees. You can export everything we hold about you from your settings, and delete your account yourself: deactivation is immediate, erasure follows a 30-day grace period.
AI features run with training disabled
Requests to AI providers are sent with data retention and training explicitly disabled. Your posts, comments and messages are processed to answer your request and are not used to train any model. The AI features are optional throughout.
API keys are scoped, and checked on every call
Keys for the API, CLI and MCP server carry explicit scopes: read, write and schedule, publish, reply. Each is checked per call, tools outside the scope are hidden rather than merely refused, and a revoked key stops on the next request. A key can never touch billing, team membership, or workspaces it was not created for. Details in the developer docs.
The boring web hygiene, verifiable from outside
Strict Content-Security-Policy, HSTS, X-Frame-Options and the rest of the header set are live on the product and checkable from any terminal. Rate limits protect the authentication routes. Webhook payloads are signature-verified. None of this is exotic; the point is that it is actually in place.
What we don't claim
Echoia holds no SOC 2 or ISO 27001 certification today: those audits cost more than a young bootstrapped product can justify, and pretending otherwise with badge-shaped marketing would be worse than saying it plainly. What we offer instead is this page, a privacy policy that names every subprocessor, and a founder you can write to directly. If your organisation requires certified vendors, we would rather tell you now than after onboarding.
Found something?
If you believe you have found a vulnerability, write to contact@echoia.io with enough detail to reproduce it. Reports go straight to the person who wrote the code, answers come quickly, and good-faith research on your own account will never be met with legal threats.