Yaziio logoYaziio

Security

How Yaziio protects data; only what the application actually does.

In short: Working today: notifications from Meta are verified by signature, the site is served over HTTPS with security headers and uses no cookies. Planned (not live yet): encrypted storage of access tokens, automatic deletion/anonymisation with a default target of 180 days, and a management dashboard that will not be opened to the public internet.

What works today and what is planned

Working

Webhook signature check

Every notification from Meta is verified with an X-Hub-Signature-256 (HMAC-SHA256) signature. Requests with an invalid signature are rejected; if the signature cannot be verified, no event is accepted. Request bodies are size-limited.

Planned

Encrypted storage

Once account connection goes live, access tokens issued by Instagram will be stored encrypted. We never ask for or see your account password.

Planned

Dashboard will not be public

The management dashboard is planned and will not be opened to the public internet; it will be reachable only from authorised devices. Today only this site and the webhook endpoint are exposed to the internet.

Planned

Default target: 180 days

Our default target is 180 days; automatic deletion/anonymisation will be added when the application goes live. Today there is no automatic deletion; deletion requests are handled by email.

Your rights

Deletion request

To have your data deleted, follow the steps on the Data Deletion page or write to us by email.

Working

No cookies, no third-party scripts

The site uses no cookies and loads no third-party tracking or advertising scripts; fonts and images are served from the site itself. It is served over HTTPS and sends security headers.

What we do not claim

Yaziio currently has no independent security certification or audit report such as ISO 27001 or SOC 2, and we make no such compliance claim. This page separates what works today from what is planned. For AI processing and third parties see the Privacy Policy and the AI Disclosure.

Reporting a vulnerability

If you notice a security issue, please write to [email protected]. Contact details are also available in machine-readable form in security.txt.

Questions, or want access?

There is no form; just email us.

[email protected] FAQ

Last updated: