Skip to content

Trust at Postly

Information Security Program

Postly Technologies, Inc. maintains administrative, technical, and organizational safeguards designed to protect customer data and the systems that deliver Postly services.

Effective July 31, 2026Reviewed at least annually

Core security practices

Our controls are selected and maintained according to the nature of the service, the sensitivity of the data, and applicable legal and contractual obligations.

Security governance

Postly maintains an information security program with assigned ownership, documented standards, periodic review, and risk-based updates.

Access control

Access is authenticated and limited according to role, responsibility, and least privilege. Elevated and production access is restricted and reviewed.

Data protection

We use safeguards designed to protect sensitive data in transit and at rest, manage secrets outside source code, and limit access to customer information.

Application security

Security is considered throughout development and deployment through code review, automated checks, dependency maintenance, authentication controls, and controlled releases.

Infrastructure protection

Production services are separated by function, exposed through controlled routes, monitored for availability, and protected using provider and platform security controls.

Vulnerability management

Reported and identified vulnerabilities are assessed, prioritized by risk, remediated, and tracked through closure. Critical issues receive expedited handling.

Incident response

Postly maintains procedures to identify, contain, investigate, remediate, and learn from security incidents, including notification when required by law or contract.

Workforce and endpoint security

Personnel with system access must follow baseline security requirements, including strong authentication, supported devices, endpoint protection, screen locking, and secure handling of data.

Privacy and data lifecycle

Our security program works alongside our privacy program. Postly supports account deletion, responds to valid privacy requests for personal data Postly directly holds, and retains that data only as described in our legal commitments and operational retention requirements.

Third-party publishing scope

Postly helps customers publish customer-provided content to supported social networks, commerce services, and other third-party platforms. Publishing content does not make Postly the handler of a platform's audience, shopper, buyer, follower, or other end-user records. Postly does not fulfill requests to access, update, delete, or provide underlying end-user data that Postly does not hold or control.

Report a security concern

If you believe you have found a security issue affecting Postly or customer data, please contact us with enough detail to investigate. Do not access, modify, or retain data that does not belong to you.

Contact Postly Security
This overview describes Postly's security program at a high level and does not disclose confidential control configurations or create rights beyond an applicable written agreement.