Security center

Guardrails for human-in-the-loop marketplace automation

SoukSync uses signed service calls, encrypted credential storage, scoped account access, and explicit marketplace prerequisite checks. These are implemented controls, not a claim of third-party certification.

Controls in place today

  • App-to-worker automation requests require timestamped HMAC signatures and reject stale payloads.
  • Marketplace credential material is encrypted before persistence and encryption keys fail closed in production.
  • Sensitive publishing and connection actions require an authenticated, verified account.
  • Public health responses expose service state without revealing provider configuration.
Report a suspected security issue privately to security@souksync.com. Do not include marketplace passwords, session cookies, or other secrets in the initial message.