IgniteViral

Trust

Security at IgniteViral

You trust us with access to your social accounts and business data. Here is how we protect it.

Hashed passwords

Passwords are hashed with bcrypt (cost factor 12) before they are stored. We never store or log plain-text passwords.

Signed sessions

Sign-in sessions are signed tokens issued by NextAuth. Signing out clears the session cookies on your device.

OAuth with state & PKCE

Connecting Instagram, Facebook, TikTok or Pinterest uses OAuth. Each flow is protected with a one-time state value and, where supported, PKCE — we never ask for your social media passwords.

Per-account data isolation

Every API request is checked against your session, and records such as products, watchlists, wallets and stream plans are scoped to your user ID.

Safe website scanning

Store and product URLs you submit are validated before we fetch them. Private network and internal addresses are blocked to prevent server-side request forgery.

Content Security Policy

Pages are served with a Content Security Policy that restricts which origins may load scripts and connect to APIs.

Crypto wallets

The Add Wallet feature only stores public information you type in: a wallet name, network, optional public address and the amounts you hold. IgniteViral will never ask for a private key or seed phrase — if anyone does, it is not us.

What you can do

  • Use a unique, strong password for IgniteViral.
  • Disconnect social accounts you no longer publish to.
  • Sign out on shared devices.

Reporting a vulnerability

If you believe you have found a security issue, please report it privately through the contact page with steps to reproduce. Please do not access other users’ data or disrupt the service while testing. We will acknowledge your report and keep you updated while we fix it.

Privacy

For what data we collect and your rights over it, see the Privacy Policy and Cookie Policy.

Security | IgniteViral