Overview
We apply administrative, technical, and organisational measures designed to protect accounts and data. No internet service is perfectly secure; we continuously improve controls.
We do not claim third-party certifications (such as ISO or SOC) that we have not obtained.
Encryption and transport
Public traffic to the platform is served over HTTPS/TLS.
Secrets and credentials are stored using platform secret management practices and are not committed to source control.
Authentication and sessions
Registered users authenticate with account credentials and session tokens.
We support account logout and token invalidation on logout flows.
Access to product modules is gated by authentication and, where applicable, role-based permissions and tenant isolation.
Application controls
API routes use request validation, rate limiting where appropriate, and structured error responses that avoid leaking stack traces to clients.
Tenant-scoped product data is authorised per brand membership and permission checks.
Responsible disclosure
If you believe you have found a security vulnerability, email support@toptrends.reviews with a clear description and steps to reproduce. Please do not exploit production data or disrupt availability.
We will acknowledge reports and work to remediate confirmed issues in a reasonable timeframe.
Best practices for customers
Use strong unique passwords, protect API keys, review AI outputs before publishing, and grant Social Studio roles using least privilege.