Transport and browser controls
HTTPS, HSTS, restrictive content security policy, framing protection, MIME sniffing protection, and limited browser permissions protect the public surface.
DATA SECURITY
Vielumi separates public information, Content Posting operations, and internal Marketing API access. Controls are designed to minimize credential exposure and keep advertiser actions accountable.
HTTPS, HSTS, restrictive content security policy, framing protection, MIME sniffing protection, and limited browser permissions protect the public surface.
App secrets and access tokens are not placed in public pages or browser storage. Stored tokens are encrypted and handled only by server-side processes.
Restricted personnel access, role checks, least privilege, authorization review, and prompt access removal reduce unnecessary account exposure.
Short-lived state values, exact redirect URI validation, permission review, advertiser-ID checks, and revocation handling protect the authorization flow.
Security-relevant authorization and administrative events are logged for operational review, incident investigation, and account protection.
The integration requests only data needed for documented advertising functions and does not expose Marketing API data to the separate Content Posting product.
REPORT A SECURITY ISSUE
Send a concise description to info@vielumi-global.com. Do not include active credentials or sensitive advertiser data in the first message.