Skip to content
sendgecko

Security

How SendGecko protects your accounts, tokens and content, and how to report a vulnerability.

Last updated

You trust SendGecko with the keys to your social accounts, so we treat security as a feature, not a footnote. This page explains what we do and how to tell us if you find a problem. We describe what is real today, not wishes.

Signing in

  • SendGecko has no passwords. You sign in with a passkey (Face ID, Touch ID, Windows Hello or a security key), a one-time code sent to your email, or Google.
  • Sessions can be reviewed and ended in Settings → Security. Sign-in attempts are rate limited, and sign-in and sign-up forms are protected against bots.
  • Cookies are HttpOnly and secure, so scripts on a page can't read your session.

Your tokens and keys

  • OAuth access and refresh tokens, Bluesky app passwords, Viber channel tokens, Discord webhook URLs and your own AI provider keys are encrypted with AES-256-GCM before they reach the database. Encryption keys are versioned, so they can be rotated without downtime, and are kept apart from the data.
  • Secrets are never written to logs. Error reports have tokens and keys removed before they leave our servers. The app shows you only a short hint of an AI key, never the whole key.
  • We delete credentials the moment you disconnect a channel or the network tells us access was revoked.

Smallest possible access

  • We use each network's official API and request only the permissions we need (the full list is in the Privacy Policy). We never use scraping, passwords, or automation of other people's accounts.
  • Your data is separated by workspace. Every request is checked for membership and role, so one customer can't reach another's content.
  • Staff access to production data is limited to what is needed to run and support the Service.

How the platform is built

  • Incoming webhooks from payments and messaging services are accepted only after their signature is verified, and each event is processed once.
  • Web addresses you give us (for example when you add a web page to Resources or a link card) are fetched through a protected fetcher that refuses private and internal addresses.
  • Uploads are checked by their real file type and size, and location data is removed from photos. Public media links use random addresses.
  • Publishing is safe to repeat. The database is the source of truth; if we aren't sure a post went out, we check before trying again, so you never get a double post.
  • Website protections: HTTPS everywhere with HSTS, clickjacking protection, strict referrer policy and a firewall in front of the Service.

Hosting and backups

The SendGecko app runs on dedicated servers in Germany (netcup), behind Cloudflare. The website is served by Cloudflare. Media is stored in Cloudflare R2. A full list of providers is on Subprocessors.

The database is backed up every night. Backups are encrypted, kept for 30 days, and restore-tested regularly. A log of sensitive actions (connecting a channel, changing members, billing changes) is kept for security and for you.

AI and your data

Gecko AI only sends a model what a request needs. It never sees tokens or data from the networks, and it can't publish anything on its own. Details are in the Privacy Policy.

If something goes wrong

We have an incident process: contain, fix, tell affected customers, and learn. If a breach affects personal data, we notify customers without undue delay and the authorities within the legal deadline (72 hours under GDPR).

Report a vulnerability

We welcome reports from security researchers. Email contact@sendgecko.io with what you found, steps to reproduce and the impact. Our machine-readable contact is at /.well-known/security.txt.

  • We'll acknowledge your report within 3 business days and keep you updated.
  • Please give us a reasonable time to fix the problem before telling anyone else, and avoid privacy violations, data destruction and service disruption. Don't access or change other people's data: use your own test accounts.
  • If you follow these rules and act in good faith, we won't take legal action against you and we'll credit you if you wish.
  • In scope: sendgecko.io and app.sendgecko.io. Out of scope: denial-of-service, social engineering of our team, and issues in the networks' own services.

We don't run a paid bounty programme yet, but we say thank you properly.

Operated by PINTECH DOO Skopje, Skopje, North Macedonia.