Operational safeguards

Security built around connected-account control

Juno33 limits provider access to authorized accounts and keeps publication, workspace, and credential boundaries explicit.

Provider authorization

Creators authorize supported providers through the provider’s OAuth flow. Juno33 does not receive social-platform passwords. Access is limited to the scopes approved by the creator.

Credential handling

Provider access and refresh tokens are encrypted at rest, retained in server-side systems, and never intentionally exposed through public frontend environment variables.

Workspace isolation

Provider accounts, posts, schedules, and receipts remain bound to their owning workspace. Authorization checks fail closed when an identity or workspace relationship cannot be verified.

Publication integrity

Idempotency keys, publication claims, stored media hashes, processing reconciliation, and provider receipts reduce duplicate sends and prevent uncertain requests from being mislabeled as confirmed publication.

Reporting concerns

Report a suspected security or privacy issue to junomanagementus@gmail.com. Do not include passwords, access tokens, or other secrets in email.