Security
How Yaziio protects data; only what the application actually does.
In short: Notifications from Meta are verified by signature, Instagram access tokens are stored encrypted, the management dashboard is not open to the public internet and conversation data is deleted or anonymised after 180 days by default.
Webhook signature check
Every notification from Meta is verified with an X-Hub-Signature-256 (HMAC-SHA256) signature. Requests with an invalid signature are rejected; if the signature cannot be verified, no event is accepted. Request bodies are size-limited.
Encrypted storage
Access tokens issued by Instagram are stored encrypted. We never ask for or see your account password.
Not open to the internet
The management dashboard is not public; it is reachable only from authorised devices. Only this site and the webhook endpoint are exposed to the internet.
180 days
Conversation and comment content is kept for 180 days by default, then deleted or anonymised so it can no longer identify a person.
Deletion request
To have your data deleted, follow the steps on the Data Deletion page or write to us by email.
No cookies, no third-party scripts
The site uses no cookies and loads no third-party tracking or advertising scripts; fonts and images are served from the site itself. It is served over HTTPS and sends security headers.
What we do not claim
Yaziio currently has no independent security certification or audit report such as ISO 27001 or SOC 2, and we make no such compliance claim. Every statement on this page describes the application's real behaviour. For AI processing and third parties see the Privacy Policy and the AI Disclosure.
Reporting a vulnerability
If you notice a security issue, please write to [email protected]. Contact details are also available in machine-readable form in security.txt.
Questions, or want access?
There is no form; just email us.
[email protected] FAQ