Security

MetaFix AI is built so that the sensitive parts of your Meta relationship stay with Meta.

What we never ask for

We never request or store Facebook passwords, two-factor codes, session tokens or browser cookies. There is no scenario in which MetaFix AI needs them.

We never attempt to bypass Meta security, permissions, restrictions or review systems.

How Pages are connected

Pages are connected exclusively through official Meta OAuth. You see a plain-language explanation of every permission before authorization begins, and we request only the permissions required for the features you use.

Access tokens are held server-side, never exposed to the browser, and never written to local storage.

Data isolation

Every record belongs to an organization. Database row-level security enforces that members can read only the organizations they belong to, and role-based access controls what each member can change.

Evidence files are stored privately and served through short-lived signed URLs.

Auditability

Sensitive actions are recorded in an organization audit log with the acting user, resource and timestamp. Administrators can never view Facebook credentials, because we never hold them.