Security
Security is designed into every layer of Nexus, from how you sign in to how account data is stored.
TikTok Permissions We Request
Every TikTok permission Nexus requests maps directly to a visible feature — the same principle applies to every other connected platform (Facebook, Instagram, YouTube). Nothing is requested speculatively, and no permission grants the ability to post, edit or delete content on a connected account.
user.info.basic· Active todayIdentifies the connected TikTok Business account (OpenID, display name, avatar) so administrators can see which account is linked to each brand.
user.info.profile· Activates with live AnalyticsDisplays public profile details (bio link, verification status) on the brand's Analytics overview.
user.info.stats· Activates with live AnalyticsPowers follower count, engagement rate and audience growth metrics across Analytics and AI Insights.
video.list· Activates with live AnalyticsPopulates per-video performance tables (views, likes, comments, shares) so brand managers can see what content performs best.
Authentication
Connecting an account uses each platform's own official login flow — the TikTok Login Kit (OAuth 2.0 Authorization Code Flow with PKCE/S256) for TikTok, and each platform's official OAuth 2.0 flow for Facebook, Instagram and YouTube. Authentication is always performed directly by the platform being connected — {app} never sees or stores a user's platform password.
Data Encryption
Access tokens are encrypted at rest and are exchanged, stored and refreshed exclusively on the server. They are never exposed to client-side code or transmitted to the browser.
Session Security
Administrator sessions are managed with secure, httpOnly cookies and are never used for advertising, analytics or cross-site tracking.
Company Isolation
Every company's brands, connections, and data are fully isolated from every other company on the platform. Access is scoped per company at every layer, not just per brand within one company.
Brand Isolation
Every brand's connected accounts and credentials are isolated from one another. An administrator's access to one brand's platform connections never exposes another brand's data.
CSRF Protection
Every OAuth connection flow is protected by a signed, single-use state value paired with a short-lived, httpOnly cookie. A callback is only completed when both match and the attempt hasn't expired — this is checked before any token exchange is even attempted.
Environment Separation
Sandbox and Production use separate, independently configured credentials for each platform. Switching environments is a deliberate administrator action, never automatic or implicit.
Publishing Safety
Publishing real content to a connected platform is disabled by default and gated behind multiple independent safeguards: a code-level dry-run switch, a separate deployment-level authorization flag, and an explicit allowlist naming the exact test brand and test account permitted to use it. All must agree before any real publish attempt can occur, and real publishing remains unavailable for every brand outside that explicit allowlist.
Audit Logging
Connections, disconnections, and other sensitive account actions are recorded in an activity log visible to authorized administrators, so changes to a brand's platform connections are always traceable.
Account Disconnect
An administrator can disconnect any connected platform account at any time. Disconnecting revokes the stored access on both Nexus and the connected platform where the platform supports revocation, and removes the encrypted credentials immediately.
Responsible Disclosure
If you believe you've found a security vulnerability, please report it privately to souadtorfi10@gmail.com rather than filing a public issue. We aim to acknowledge reports within two business days.