Platform

Tamanor security

Tamanor connects only through official OAuth, never scrapes, never stores passwords, keeps tokens server-side and out of logs, and is read-only by default with human approval before any action.

Connections

Official OAuth and API integrations only. Tamanor never scrapes any platform and never asks for or stores social passwords. Platform capability checks run before any action is offered.

Tokens

OAuth tokens are stored server-side only, encrypted at rest in production. They are never shown in the interface, never written to logs, and never included in the audit trail.

Isolation & audit

Every tenant's data is isolated by PostgreSQL row-level security. Every meaningful action is recorded in an append-only audit log.

Frequently asked questions

Do you store my social password?
Never. Tamanor uses official OAuth; passwords are never requested or stored.
Are tokens ever logged?
No. Tokens are kept out of logs, the UI, error messages and the audit trail.
Security — Tamanor OAuth-only, read-only by default