---
id: public-ai.security-and-privacy
locale: en
visibility: PUBLIC
status: LIVE
last_reviewed: 2026-07-26
owner: Influblog Security and Privacy
---

<!-- Generated from the curated public AI documentation allowlist. Do not edit this file directly. -->

# Security and privacy

Influblog separates public product information from internal company
knowledge, tenant data, and executable operations.

## Availability

**Status:** LIVE as a platform boundary. Future AI interfaces remain subject to
the same role, tenant, consent, and audit requirements as human-facing
interfaces.

## Role and tenant boundaries

Brands, creators, agencies, and administrators use different roles and product
surfaces. Access is checked on the server. Brand Website scope separates
website-specific campaigns, products, integrations, affiliate activity, and
related reporting inside a brand company.

Agency access depends on an explicit managed-brand or represented-creator
relationship. Administrator access is operational and audited; it is not a
public data source.

## Data categories

Public documentation describes product concepts. It does not contain customer
campaigns, creator contact details, private messages, individual contracts,
wallet balances, unpublished analytics, credentials, or internal operational
records.

Media and documents follow the same relationship and tenant rules as their
database records. Possessing a storage identifier or guessed URL is not
authorization.

## Consent and integrations

Social and commerce connections require the relevant account authorization and
provider permissions. Creator analytics also depends on creator consent.
Integration credentials remain server-side and are not exposed through public
documentation.

## AI and agents

Public AI discovery is read-only product documentation. Influblog does not
currently publish a general customer OpenAPI or MCP interface. Future
authorized agents must use allowlisted operations, validated inputs, scoped
actor context, and audit logs. Planned write actions require preview,
confirmation, idempotency, and a fresh permission check.

See the public [Privacy policy](https://influblog.com/privacy) and
[Terms](https://influblog.com/terms) for the current public policies.
