Security
How a delivered Content Factory instance is built to fail closed, not open.
API-key authentication
Every control endpoint (generate a draft, approve, schedule, publish) requires an X-API-Key header. No key configured means every request is rejected — the system fails closed, never open.
Encryption in transit
All traffic to and from a delivered instance runs over TLS, including the exchange with your LLM provider and every connected publishing platform's API.
Your content and clients stay yours
Generated content and client review links live in the destination you configure — your dashboard, your CRM, your infrastructure. We don't retain a copy or route it through a third-party store we control.
Bring your own credentials
The AI provider key and every publishing-platform token the build uses are yours. You control the accounts, the spend, and can revoke access at any time. We don't hold a standing copy of your keys after delivery.
Client review links, scoped
External sign-off portals are single-purpose links scoped to the specific content batch under review — they don't expose your dashboard, your other clients, or any data beyond what's under review.
Credential handling during support
If a support task requires access to your environment, access is scoped to that specific task and time-boxed. We do not request or hold standing admin credentials as a condition of delivery.
Incident response
If a security issue affecting a delivered build is identified, we notify the affected party without undue delay, describe the exposure plainly, and ship a fix on a priority track.
Responsible disclosure
If you believe you've found a vulnerability in a delivered build or on this site, contact us through the channel you used to place your order. Describe the issue and, if possible, steps to reproduce it. We take reports seriously, do not pursue legal action against good-faith researchers who report responsibly, and will confirm receipt and a fix timeline directly.