Sprout Content Operations

Practical controls around every connected account

Our current controls are described here without implying certifications that the service has not obtained. Security-sensitive features fail closed when required configuration is missing.

No password collection

Sprout does not request or store TikTok account passwords.

Encrypted authorization tokens

OAuth access and refresh tokens are encrypted before storage. Decryption occurs only on the server immediately before an authorized provider request.

Server-side credentials

Platform credentials are stored only in server-side environment variables and are never returned to browser clients.

Account control

Users may disconnect an account and stop future data synchronization. Disconnecting clears stored access and refresh tokens.

Audit records

Application actions are recorded in audit logs with redacted metadata. Necessary records are anonymized when imported account data is deleted.

Restricted workspace

Access to the workspace is restricted to authorized users through a secure HttpOnly session cookie and role checks.