Security & privacy

Trust is a product behavior.

QueueTempo is designed to keep brand data scoped, social credentials encrypted, publishing inspectable, and administrative power narrow and auditable.

Security foundations

Specific controls, not vague assurances.

Each control below is part of how QueueTempo is built and operated, covering infrastructure, external accounts, controlled live tests, restore drills, and monitoring.

Official OAuth

QueueTempo requests only the approved scopes needed for the selected capability. It never asks for social passwords or automates a consumer site.

Encrypted tokens

Social access and refresh tokens use versioned authenticated encryption. Keys live in a secret store, with rotation and compromise runbooks.

Tenant isolation

Every Organization-owned query, file, cache key, background event, and authorization decision stays scoped to that Organization.

Role enforcement

Membership and permission checks happen on the server. Owners, Admins, Publishers, Approvers, and Analysts receive distinct authority.

Audit trails

Sensitive Organization, publishing, billing, membership, and support actions record the actor, target, time, and safe reason.

Stripe payments

Self-serve checkout and payment-method management use Stripe-hosted flows. Signed webhooks-not success-page parameters-drive billing state.

Backups & recovery

Encrypted backups, documented retention, point-in-time recovery where the provider supports it, and rehearsed restore drills.

Export & deletion

Account and Organization export, deletion, token revocation, active-data purge, backup aging, and legal-hold behavior follow documented workflows.

Private by default

Customer prompts, brand facts, sources, unpublished drafts, media, and private analytics are not QueueTempo marketing inventory.

Authorization path

Every protected request earns access again.

A valid session is only the first check. The server resolves the Organization, loads active membership, verifies the exact permission, and fetches the target inside that Organization scope before a transaction can change it.

  • Verified email for publishing, billing, invitations, and sensitive changes
  • Recent authentication for ownership transfer, deletion, and security settings
  • Protected browser mutations with origin and CSRF defenses
  • Session listing, revocation, fixation prevention, and secure cookies
  • Last-owner protection and auditable ownership transfer

Protected mutation

01Authenticate Account
02Resolve Organization
03Load active membership
04Verify exact permission
05Load target in tenant scope
06Mutate and audit transactionally

Publishing credentials

Social tokens stay out of normal sight.

A Connection exposes safe identity, capabilities, scopes, health, and reconnect actions-not decrypted OAuth credentials.

QueueTempo stores

  • Encrypted provider access and refresh credentials
  • Safe provider identity and concrete Channel identifiers
  • Granted scopes, capability observation date, and health
  • Refresh, revoke, and provider-response metadata needed for recovery

QueueTempo does not collect or log

  • Social passwords
  • Access or refresh tokens in telemetry
  • Authentication cookies or reset links
  • Full customer prompts, sources, or drafts by default
  • Signed private-media URLs or payment details

Claims ledger

What QueueTempo does-and does not-claim.

A security page should separate the controls QueueTempo operates from the third-party certifications it does not hold.

Official OAuth only

Every Connection runs through the provider's own consent screen. QueueTempo never collects a provider password or drives a browser session on your behalf.

Required control
Encrypted social tokens

Versioned encryption, redaction, rotation, revoke, and compromise procedures.

Required control
SOC 2 report

No report is claimed on this site.

Not established
ISO 27001 certification

No certification is claimed on this site.

Not established
HIPAA support

QueueTempo is not marketed as a system for protected health information.

Not offered
Uptime SLA

No public numerical SLA is claimed. Enterprise terms exist only by contract.

Not established

Subprocessor categories

HostingVercel
DatabaseManaged PostgreSQL provider
AI draftingOpenAI
PaymentsStripe
EmailTransactional email provider
StorageManaged private object storage

Subprocessors

Only providers needed to run the service.

QueueTempo’s subprocessor list names the hosting, database, AI, payment, email, storage, and monitoring providers it relies on, what each one processes, and the relevant data location.

OpenAI and other AI providers receive only the customer-selected context needed for the requested draft. QueueTempo does not send hidden reasoning to customer logs and does not use private customer content as general marketing material.

Set the next beat

Build a publishing rhythm you can inspect.

Start free, keep automatic publishing off until you trust the setup, and use Organization-level pause controls whenever you need them.