We take a practical, transparent approach to security. Here's exactly what we do — and what we don't claim.
When you connect third-party services like Google, Instagram, Facebook, or LinkedIn, Click It uses OAuth 2.0. This means you authorize access through the provider's secure login flow, and Click It never sees or stores your provider passwords. You can review and revoke access at any time from the provider's settings or from within Click It.
OAuth access tokens and refresh tokens obtained from third-party providers are stored in our backend database with encryption at rest. Tokens are used only to perform the actions you explicitly request, such as scheduling posts or sending messages through connected accounts.
Click It uses workspace-level data isolation. Each workspace has its own leads, content, campaigns, and integrations. Data from one workspace is not accessible by users in another workspace. Role-based access controls within each workspace determine who can view, edit, or manage specific resources.
You can disconnect any third-party integration at any time from your Settings page. Disconnecting revokes Click It's access to that service and stops all associated workflows, syncing, and data collection from that provider.
For integrations that use webhooks (such as Stripe billing events and Meta platform notifications), Click It verifies cryptographic signatures on incoming requests to ensure they originate from the claimed provider. Unverified requests are rejected.
Administrative actions — such as managing users, viewing billing details, and accessing platform-level settings — are restricted to users with admin roles. Route guards enforce these restrictions on both the frontend and backend. Regular users cannot access admin-only pages or perform admin-only actions.
We believe in being honest about what security measures are in place. We do not use terms like "military-grade," "bank-level," "100% secure," or "unhackable" — because no system can truthfully make those claims.
Security is an ongoing practice, not a one-time achievement. If you discover a vulnerability or have a security concern, please contact our support team from within the app.