Security

Local-first controls with fail-closed publishing behavior.

AccountPilot is designed to stop or require attention when authorization, current TikTok settings, media state or publishing outcome is uncertain.

✓

Authorized accounts

Publishing actions depend on valid platform authorization and the required permission for the connected creator.

●

Protected credentials

Ordinary user-facing responses are designed not to expose access tokens, refresh tokens, client secrets or temporary signed upload URLs.

1×

Duplicate prevention

Durable publishing state is recorded so ambiguous Direct Post initialization is not treated as permission to blindly initialize another post.

R

Publishing settings recheck

Publishing fields are revalidated so stale TikTok choices can be invalidated before execution.

DB

Local operational data

Publishing jobs, schedules and operational history can be stored locally as part of the desktop workspace.

!

Fail closed

Unknown or inconsistent state is treated as a reason to pause, block or require manual attention rather than silently continue.

Security contact

Report a security concern to GudLabs.

Include the affected page or product area and enough detail for the issue to be reproduced safely. Do not email passwords, access tokens or other secrets.

Report security issue