Studio Security

Security

Leanboat Studio never receives your social passwords. Accounts are authorised on each platform’s own login screen, and you can revoke that access from your own settings at any time. Card details go to the payment processor and never reach the product. Nothing publishes to your accounts without your approval.

What we hold, and what we don’t

Social passwordsNever. Authorisation happens on the platform, and what's stored is a revocable token held by the publishing layer.
Card detailsNever. Checkout runs on the payment processor's own pages, and the product stores only a subscription reference.
Your content and your brand fileYes, because the service can't run without them. Both are yours and both are readable by you.
Post performanceYes, read from the accounts you connected, which is what the learning loop runs on.

How approval links work

The weekly approval email opens without a login, which is the point: an approval that requires remembering a password is an approval that doesn’t happen. The link carries a signed token that expires, so it can’t be reused indefinitely or guessed, and approving twice changes nothing the second time.

Revoking access

You do not have to ask us. Every connected account can be disconnected from inside the product, and independently from your own settings on Instagram, LinkedIn, Facebook or X. Doing it on the platform’s side works whether or not we are involved, which is how it should be.

What we don’t claim

No certifications, no completed third-party audit, no penetration-test report. Studio is a young product, and saying so is more useful than a badge that means less than it looks like it does. If your procurement process needs specific assurances, ask before you buy rather than after.

Reporting something

If you find a security problem, tell us before you tell anyone else and we will treat it seriously and quickly. Write to hello@leanboat.io.