Security & user control
This page is maintained by CAEVIX to answer common security and privacy questions about CAEVIX HQ. It describes controls that are part of the product today; it is not an independent certification.
Official OAuth is used
Every platform connection is established through that platform's own OAuth authorization flow. CAEVIX only receives the scopes the account owner grants.
Platform passwords are never collected
CAEVIX never asks for, stores or transmits TikTok, Pinterest, YouTube or Amazon passwords. Credentials are entered on the platform's own domain.
Tokens are stored securely server-side
Access and refresh tokens are encrypted at rest and used only from the server. They are never sent to the browser or exposed in the public website.
Users control which accounts are connected
Connections are made per account, from inside the signed-in app, by the account owner.
Users can disconnect at any time
Disconnecting an account in CAEVIX removes the stored tokens, and access can also be revoked from the platform's own settings.
Content is reviewed before publishing
Where review is configured, drafts wait in a review screen and are only published through the official API after the user approves them.
Authenticated data is not publicly exposed
Dashboards, analytics, connected accounts and publishing are behind authentication. This public website shows only product information and clearly labelled sample data.
Failures are recorded truthfully
When a platform API rejects a request, CAEVIX stores and shows the exact response. A publish is never reported as successful unless the platform confirms it.