Security and privacy

Your data stays yours.

Social Monkey holds your customer list, your inbox, and everything you have taught your agent. Here is how that is kept safe, and what we will never do with it.

We do not sell it, and we do not use it to train general AI models. Ask for a copy or ask us to delete it, and we will.

Our promises
Walled offNo business sees another
EncryptedTokens locked at rest
You approveNothing sends on its own
LoggedEvery move is written down

Your business

Customers
Inbox
Memory

Another business

Another business

Row-level security

One business, one wall

Separated at the database.

Every row we store carries the business it belongs to, and the database itself refuses to hand it to anyone else. It is not a filter in our code. It is a rule the data lives under.

That rule covers every table we store, and a new one without it fails our build. A mistake in our own app still cannot show one business another’s data.

Keys and access

Locked, and only your people.

The tokens that let your agent post are encrypted with AES-256-GCM before they are stored. What sits in the database is ciphertext, not a key someone could walk off with.

You choose who joins your workspace and what they can do. Turn on the authenticator step and a stolen password is not enough to get in on its own.

How it is locked
AES-256-GCMHow your platform tokens are stored
Server-side onlyKeys never leave our servers
Roles you setChoose who joins and what they do
Authenticator sign-inAdd a 6-digit step to every login
  1. Your agent drafts

    Draft

    A post, a reply, or a campaign.

  2. You approve

    Your gate

    Nothing moves until you say so.

  3. It sends

    Publish

    On the schedule you picked.

  4. It is logged

    Record

    What it did, when, and how it went.

Nothing goes out unseen

Nothing sends without you.

Your agent drafts. You approve. Posts, replies, and campaigns wait on your say-so before they reach a customer, and autopilot is scheduling, not sending.

Texts follow the same rule the law does: consent is recorded rather than assumed, STOP is honoured, and nothing goes out before 9am or after 8pm.

Checked, and checked again

We check our own work.

We run 14 automated security audits over the database rules, secrets, sign-in, uploads, and more. They have to pass before a release goes out.

On top of that we map our work to a 48-control industry checklist, keep an incident runbook, and rehearse a full restore every quarter.

CASA verified
48Controls mappedAgainst the CASA v2.1.1 list
14Automated auditsDatabase, auth, crypto, uploads
60Minutes to containThe first step of our runbook
4Restore drills a yearOne rehearsal every quarter

Still have questions

Ask us anything.

Found a problem? Write to security@socialmonkeyai.com. We acknowledge reports within two business days and aim to contain critical issues within 24 hours.

Start free trial