Security

A smaller trust surface for social automation.

PubMesh is designed so AI clients operate bounded product capabilities instead of receiving raw social-provider credentials.

Credential boundaries

Social provider credentials remain behind PubMesh and its execution adapter. External clients work through PubMesh authorization and typed actions.

Workspace isolation

Connections, media, usage and publishing operations are scoped to a workspace. Product APIs resolve the authenticated user and workspace before accessing workspace-owned resources.

Explicit public actions

Drafting and live publishing are distinct operations. This keeps reversible preparation separate from actions that alter a public social account.

Secrets

Production secrets are treated as runtime configuration and are not intended for browser exposure. Provider credentials should be rotated if disclosure is suspected.

Report an issue

Security reporting and a dedicated disclosure mailbox will be published before general availability. Until then, do not include credentials or access tokens in ordinary support messages.