PhoenixPhoenix Autopilot
PrivacyContactBack to app
Trust

Security is part of the product.

Phoenix is designed to keep account credentials and provider secrets on the backend while giving you a clear, reviewable workspace.

Security overview · Updated August 2026

Account protection

Passwords are stored as salted scrypt hashes. Sessions use HttpOnly cookies and expire automatically. Content records are scoped to the signed-in account.

Secrets and integrations

AI, search, Supabase, and TikTok credentials are read by the server and are not placed in frontend JavaScript. TikTok access is granted through OAuth and can be revoked from TikTok account settings.

Content review

Generated content is stored as a draft or waiting for approval according to workspace settings. Phoenix does not guarantee that AI output is accurate, safe, rights-cleared, or suitable for publication.

Responsible disclosure

If you find a security issue, do not post credentials or private data in a public issue. Contact the owner of the Phoenix deployment with the affected page, impact, and steps to reproduce.

No online service can promise absolute security. Keep your password private, rotate compromised provider keys, and revoke integrations you no longer use.
Phoenix
PhoenixAutopilot

AI-assisted. Human-reviewed.

ProductContent studioTikTok publishingHow it works
CompanyAbout PhoenixContact & supportSecurity
ResourcesHelp centerCookie policyPrivacy policy
LegalTerms of servicePrivacy policyCookies
© 2026 Phoenix AutopilotSecurity overview