Security

Local-first controls with fail-closed publishing behavior.

AccountPilot is designed to stop or require review when authorization, creator capability, approved settings, media state or publishing outcome is uncertain.

Authorized accounts

Publishing actions depend on valid platform authorization and the required permission for the connected creator.

Protected credentials

Ordinary user-facing responses are designed not to expose access tokens, refresh tokens, client secrets or temporary signed upload URLs.

Duplicate prevention

Durable publishing state is recorded so ambiguous Direct Post initialization is not treated as permission to blindly initialize another post.

R

Creator review state

Protected publishing fields are reviewed as part of the job lifecycle so stale choices can be invalidated before execution.

DB

Local operational data

Publishing jobs, schedules and operational history can be stored locally as part of the desktop workspace.

!

Fail closed

Unknown or inconsistent state is treated as a reason to pause, block or require manual review rather than silently continue.

Security contact

Report a security concern to GudLabs.

Include the affected page or product area and enough detail for the issue to be reproduced safely. Do not email passwords, access tokens or other secrets.

Report security issue