Trust
Security
Last updated: August 29, 2026
A plain-English overview of how VivAddie protects your account, your brand data and your connected social accounts. We describe what we actually do — no certifications we don't hold, no guarantees no one can make.
1. Authentication and access control
Access to VivAddie requires an authenticated account. Application routes and data are gated so that each signed-in user can only reach the workspaces, brands and campaigns that belong to them. Sensitive server operations verify the caller's session before acting.
2. Database and storage protections
Your data lives in a managed cloud database with row-level access controls: every query is checked against the signed-in user's identity so one account cannot read or write another account's rows. Uploaded files and generated assets are stored in access-controlled cloud storage rather than on public paths.
3. Integration credentials and tokens
When you connect a social platform such as Meta, the access tokens that authorize publishing are handled and stored on our servers — never in your browser and never in client-side code. Where possible, connection metadata (which pages or accounts you connected) is stored separately from the secrets that authorize actions, so routine product screens never need to touch the secrets themselves.
4. Encryption
Traffic between your browser and VivAddie is encrypted in transit using TLS. Data at rest is encrypted by the managed infrastructure providers we rely on, under their platform-level encryption controls.
5. Least privilege
Internal systems and service roles are granted only the access they need to do their job. Privileged server-side operations are kept out of the client entirely and are invoked only after the caller's identity and permissions are verified.
6. Logging, monitoring and errors
We maintain operational logs and error reporting to detect problems, investigate failures and keep the service reliable. Logs are access-controlled and used for operation and security purposes, not for advertising.
7. Third-party dependencies
VivAddie runs on third-party infrastructure — cloud hosting, database, storage, AI and social-platform providers. We choose providers with strong security postures, but their own security ultimately operates under their terms. The availability and behavior of connected platforms (for example Meta) are outside our control.
8. Your responsibilities
Security is shared. To protect your account:
- Use a strong, unique password and keep your credentials confidential
- Review connected social accounts and disconnect any you no longer use
- Sign out on shared devices
- Tell us promptly if you suspect unauthorized access to your account
9. Reporting a security issue
If you believe you have found a vulnerability or a security incident involving VivAddie, please report it to security@vivaddie.com. We will acknowledge and investigate good-faith reports. Please do not publicly disclose an issue before we have had a reasonable opportunity to address it.
10. No absolute security
No method of transmission or storage is completely secure, and we do not claim otherwise. This page describes the measures we take in good faith; it is not a warranty. For how we handle your information, see the Privacy Policy.
