Official authorization
Supported accounts connect through the official OAuth or business authorization flow provided by the relevant platform. Noryun does not request the password a user uses on that platform.
Access control
Existing Noryun infrastructure enforces organization and workspace boundaries, role-based permissions, request identifiers, and audit events. The isolated reviewer workspace is protected by a dedicated role and workspace-mode check. Temporary credentials and platform-specific access remain disabled until their tests and reviewer materials are approved.
Credential protection
Secrets are not committed to source control or exposed in browser bundles. Production platform credentials will be supplied through protected secret files or a secret manager. Social token key versioning and rotation are part of the next implementation phase and are not yet claimed as production-ready.
External-write controls
External writes and AI auto-publishing are disabled by default. The required social publishing and comment-reply gates will preserve human approval and prohibit self-approval unless a separately audited emergency process is authorized.
Logging and incident response
Application logging masks common credential fields. A suspected credential exposure requires disabling external writes, stopping the affected queue, revoking affected authorization, rotating secrets, and auditing the affected time window.
Report a concern
Email security@noryun.com. Do not submit passwords, one-time codes, OAuth tokens, private keys, or identity documents through an ordinary email message.