Security

Controls you can inspect. No borrowed credibility.

Aboveboard protects the path from your workspace to a social platform with narrow access, encrypted credentials, private storage and a required human decision before publishing.

Protection by mechanism

Six controls around the work that matters

Security is not a single lock. These controls limit how credentials, content and publishing authority move through Aboveboard.

Official authorization

Connections use the authorization method the platform supports. Aboveboard does not scrape a logged-in session, reuse browser cookies or automate a browser behind your back.

Encrypted credentials

Connection credentials are encrypted at rest. They are made available only to the authorized service path that needs to call that provider.

Private media

Uploaded media stays in private object storage. Time-limited signed links handle upload and provider delivery instead of turning the bucket public.

Separated permissions

Workspace roles separate administration, drafting and approval. An editor can prepare content without gaining the reviewer’s publishing permission.

Human approval

Every outbound post stops for a person. Only an approved version can continue to the connected platform, and an edit sends it back through review.

AI and data boundaries

Aboveboard uses customer context to return the requested draft or research result, not to train a shared model. Provider handling is governed by the published privacy commitments.

The outbound path

Nothing goes straight from a prompt to a platform

Publishing is a sequence of checks. Each gate answers a different question before the next one can open.

  1. Member

    Authenticated request

    A signed-in workspace member starts the action.

  2. Role

    Permission check

    The member’s role must allow the requested operation.

  3. Person

    Explicit approval

    A permitted reviewer signs off on the exact draft.

  4. Provider

    Official API

    Only then is the approved content sent to the platform.

Your data, your exit

Control should still work when you leave

Workspace owners can export their data before leaving and delete their account from the service. Active Aboveboard data is removed under the deletion and backup-retention terms published in the Privacy Policy.

Content already published to a social platform remains subject to that platform’s own controls and retention. Disconnecting Aboveboard does not rewrite another company’s systems.

01

Export

Take a workspace data export before closing the account.

02

Disconnect

Remove a channel connection and revoke access at its platform.

03

Delete

Remove the account and its active service data under the published policy.

Clear boundaries

What Aboveboard will not do

  • Scrape logged-in platform pages or automate a browser session.

  • Put uploaded customer media in a public object-storage bucket.

  • Let drafting permission silently become publishing permission.

  • Use customer content to train a shared AI model.

  • Present an unearned certification as proof of safety.

Questions and reports

Tell a person, not a form funnel

If you have a security question or believe you found a problem, contact the support team with sensitive values removed.

support@aplora.org

Start with one channel

See whether the workflow earns your trust.

The Free plan includes the complete loop on 1 channel: sources, opportunities, drafts, review and publishing. Use the included 60 credits for roughly 15 post drafts, or mix smaller actions. No card required.