Security
Heist holds your brand's voice, your content, and the keys to your publishing channels. Here is exactly how that data is protected — no vague "bank-grade" hand-waving.
Encryption
All traffic to and from Heist is encrypted in transit with TLS (HTTPS everywhere, including the blog and marketing pages). Sensitive stored values — platform access tokens, API keys you add, and integration credentials — are encrypted at rest with AES-256-GCM before they touch the database. Our hosting provider additionally encrypts all block storage at rest by default.
Backups
The production database is backed up automatically every day, and each backup only replaces older copies after passing an integrity check. Backups are retained on a 30-day rolling window, and a separate read-only integrity check runs against the live database every 6 hours.
Data isolation
Every piece of content, Brand Brain memory, and media file is scoped to your workspace. Queries are filtered by workspace and brand at the data layer — one customer's data is never readable from another customer's account, API key, or connected AI chat.
Platform access (OAuth)
When you connect a publishing channel, Heist requests only the scopes it needs to do the job — creating and publishing posts and reading their performance. We never receive your social-account passwords: connections use each platform's official OAuth flow (Meta, LinkedIn, YouTube, TikTok, WordPress), or credentials you generate yourself in your own developer account (X). You can revoke any connection at any time from Settings → Integrations or from the platform's own security settings.
Sub-processors and connected services
Heist relies on the following services. We share the minimum data each needs to function:
- AI generation — Anthropic, OpenAI, Google, or OpenRouter, depending on which provider you configure (with your own key, your prompts and brand context are sent under your key). If you work through the MCP connector, your own AI chat (Claude, ChatGPT) does the writing.
- Payments — Stripe. We never see or store your card number.
- Hosting — Oracle Cloud Infrastructure (US region).
- Media storage — Cloudflare R2 (uploaded images and video).
- Email — Resend (verification, notifications, account email).
- Stock photos — Unsplash (search queries only).
- Voice & video rendering — ElevenLabs and Creatomate, only when you use faceless-video features.
- Sign-in & bot protection — Google (optional Google sign-in), Cloudflare Turnstile.
- Analytics — Google Analytics and Microsoft Clarity on our marketing site, blog, and app.
Deleting your data
You can export your content at any time and delete your account and data from Settings — or request deletion via our data deletion page. Deleted account data is removed within 30 days.
Reporting a vulnerability
Found something? Email support@heistbrain.com with the details — reports go straight to the engineering owner, and we'll respond as fast as we can.