Last Updated: June 12, 2026
Our Commitment to Security
At Setblue Social, security is a core part of how we build and operate our platform.
We understand that users trust us with their social media accounts, content, media assets, and publishing workflows. We take that responsibility seriously and implement technical, administrative, and operational safeguards designed to protect customer information and maintain the integrity of our services.
This Security Policy provides an overview of our security practices, vulnerability reporting process, and infrastructure protections.
Security Principles
Our security program is guided by the following principles:
Protect customer data
Secure connected social media accounts
Safeguard authentication credentials
Minimize unauthorized access
Continuously monitor and improve security controls
Respond quickly to security incidents
Maintain platform reliability and availability
Infrastructure Security
Setblue Social utilizes modern cloud-based infrastructure to operate and deliver our services.
Data Storage
Our platform currently utilizes:
Cloudflare R2 for media storage
MongoDB for user account data
MongoDB for OAuth credentials and authorization data
Network Security
We implement security controls including:
HTTPS encryption for all web traffic
TLS encryption during data transmission
Secure API communications
Network access controls
Monitoring of suspicious activity
Automated security protections where available
Authentication and Account Security
We implement safeguards designed to protect user accounts, including:
Secure authentication mechanisms
Password encryption and hashing
Session management controls
Access control restrictions
Login validation processes
Protection against unauthorized account access
Users are responsible for maintaining the confidentiality of their login credentials.
OAuth and Social Media Account Security
Setblue Social allows users to connect third-party social media platforms, including:
Threads
YouTube
When users authorize platform connections:
OAuth access tokens are stored in encrypted form.
We request only permissions necessary to provide publishing and scheduling functionality.
Connected account access can be revoked by users at any time.
Credentials are never shared with unauthorized third parties.
We do not store social media account passwords.
Data Encryption
We employ encryption measures to protect sensitive information.
Data in Transit
All communications between users and Setblue Social are encrypted using HTTPS and TLS protocols.
Sensitive Credentials
Sensitive authorization credentials, including OAuth tokens, are stored using encrypted storage mechanisms.
Application Security
We follow secure development practices designed to reduce security risks, including:
Security reviews during development
Access control enforcement
Authentication validation
Input validation
Error handling controls
Dependency and software maintenance
Ongoing platform updates
Media Security
User-uploaded images and videos are stored using cloud-based object storage services.
Access to stored media is restricted through application-level authorization controls and storage security mechanisms.
Access Controls
Access to internal systems and customer information is restricted to authorized personnel who require access to perform operational responsibilities.
Access permissions are granted according to business needs and reviewed periodically.
Monitoring and Incident Response
We monitor platform operations and investigate security-related events when identified.
Our response process may include:
Investigation of reported issues
Containment of security threats
Service remediation
User notification where required by applicable law
Security improvements following incident review
Responsible Vulnerability Disclosure
We appreciate the efforts of security researchers who help improve the security of our platform.
If you believe you have discovered a security vulnerability affecting Setblue Social, we encourage responsible disclosure.
Please Include
When reporting a vulnerability, please provide:
A summary of the issue
Detailed reproduction steps
Potential security impact
Proof-of-concept information (if available)
Browser and operating system details
Screenshots or supporting evidence where appropriate
Reporting Email
Please report security vulnerabilities to:
HYPERLINK "mailto:security@setblue.com" security@setblue.com
If this email address changes, the updated contact information will be published on our website.
Responsible Disclosure Guidelines
When conducting security research involving Setblue Social, we request that you:
Avoid accessing data belonging to other users
Avoid modifying customer information
Avoid disrupting platform availability
Avoid performing denial-of-service attacks
Avoid social engineering attacks against users or staff
Give us a reasonable opportunity to investigate and resolve issues before public disclosure
We will make reasonable efforts to acknowledge legitimate reports and investigate reported vulnerabilities promptly.
Third-Party Services
Our platform relies on third-party providers and social media platform APIs.
While we evaluate providers carefully, we cannot guarantee the security practices of third-party services outside of our direct control.
Users should also review the security and privacy practices of any connected social media platforms.
User Security Responsibilities
Users can help protect their accounts by:
Using strong, unique passwords
Protecting account credentials
Reviewing connected social media accounts regularly
Revoking unused integrations
Keeping devices and browsers updated
Reporting suspicious activity immediately
Security Limitations
While we implement commercially reasonable safeguards, no system can guarantee absolute security.
No method of electronic transmission, storage, or internet-based communication is completely secure.
Accordingly, Setblue Social cannot guarantee that unauthorized access, data loss, or security breaches will never occur.
Security Policy Updates
We may update this Security Policy periodically to reflect changes in our services, infrastructure, legal requirements, or security practices.
The updated version will be posted on our website with a revised "Last Updated" date.
Contact Us
For security-related questions or vulnerability reports:
Setblue Social
Website: "https://social.setblue.com" || “setblue.com”
Email: info@setblue.com
Address: 2nd Floor, D House, 21st Century Building, Above HDFC Bank, Ring Rd, near WTC, Udhana Darwaja, Surat, Gujarat 395002