Skip to content
Live
— GMT
INFLU
Legal

Security Summary

Last updated: 27 September 2026

Data we hold

INFLU processes two categories of data: (a) your team’s account data — name, email, role, billing information and usage preferences, processed on your behalf; and (b) public social media data — usernames, post metrics, engagement rates and content metadata collected from public Instagram profiles. The full breakdown is in our Data Processing Agreement.

Row-level security and tenant isolation

Every table that stores customer data is protected by Postgres row-level security (RLS) policies, not by application-layer filtering alone. Personal data is scoped to the authenticated user (auth.uid()); organisation/workspace data is scoped by a role ladder — owner, admin, member, viewer — enforced through SECURITY DEFINER database functions, so one workspace can never read or write another’s rows through the API. This is enforced at the database, independent of any bug in the application code that queries it.

Authentication and MFA

Accounts authenticate through Supabase Auth. Optional two-factor authentication (TOTP — any standard authenticator app) is available to every user from their account security settings and can be required for admin-level workspace actions. We do not currently mandate MFA platform-wide.

Backups

We do not currently publish a backup schedule or a contractual recovery point/recovery time objective (RPO/RTO) — that is not yet offered, and would be part of an enterprise agreement.

Breach notification

In the event of a personal data breach affecting your data, we will notify you without undue delay and within 72 hours of becoming aware of it, describing the nature of the breach, the data affected, and the steps taken or proposed. This matches the commitment in our Data Processing Agreement. To report a suspected issue: security@influ.site.

Data retention

Account and team data is retained while your account is active. When you delete your account we delete your data, except where retention is required by law. Full retention periods by data category will be set out in our Data Processing Agreement.

Not yet offered

The following are not yet offered and are listed here so procurement teams don’t have to ask: SOC 2 (Type I or II) certification, independent third-party penetration testing, and a contractual RPO/RTO. Encryption at rest on our infrastructure has not yet been independently verified and is not asserted here. These sit with our deferred enterprise layer (custom DPA, SSO/SAML, audit log) rather than this Phase 0 pack.

This security summary is provided in good faith to assist customers with their own procurement review. It does not constitute formal legal advice or a certification.

Related: Data Processing Agreement · Privacy Policy