---
id: public-ai.security-and-privacy
locale: en
visibility: PUBLIC
status: LIVE
last_reviewed: 2026-08-02
owner: Influblog Security and Privacy
---

<!-- Generated from the curated public AI documentation allowlist. Do not edit this file directly. -->

# Security and privacy

Influblog separates public product information from internal company
knowledge, tenant data, and executable operations.

## Availability

**Status:** LIVE as a platform boundary. Future AI interfaces remain subject to
the same role, tenant, consent, and audit requirements as human-facing
interfaces.

## Role and tenant boundaries

Brands, creators, agencies, and administrators use different roles and product
surfaces. Access is checked on the server. Brand Website scope separates
website-specific campaigns, products, integrations, affiliate activity, and
related reporting inside a brand company.

Agency access depends on an explicit managed-brand or represented-creator
relationship. Administrator access is operational and audited; it is not a
public data source.

## Data categories

Public documentation describes product concepts. It does not contain customer
campaigns, creator contact details, private messages, individual contracts,
wallet balances, unpublished analytics, credentials, or internal operational
records.

Media and documents follow the same relationship and tenant rules as their
database records. Possessing a storage identifier or guessed URL is not
authorization.

## Consent and integrations

Social and commerce connections require the relevant account authorization and
provider permissions. Creator analytics also depends on creator consent.
Integration credentials remain server-side and are not exposed through public
documentation.

## AI and agents

Public AI discovery remains read-only product documentation. Separately,
Influblog offers a controlled BETA MCP interface to pre-registered OAuth-PKCE
clients for Brand, Creator, and Agency users. Every grant is bound to the
signed-in person, exact role surface, tenant, approved scopes, and—where
applicable—the selected Brand Website. The allowlist exposes validated reads,
expiring safe drafts and two BETA Brand campaign-write requests. A safe draft
cannot save, publish, message, order, pay, accept a contract, change an
integration, or delete a business object.

The person can review, adopt, reject, and disconnect a client from the
corresponding Influblog role app. Revocation, rate limits, and audit remain
server-enforced. Influblog does not currently publish a general customer
OpenAPI, anonymous MCP access, dynamic client registration, or service-account
credentials.

The Brand write requests can save one AI concept as a private campaign draft
or request publication of one complete campaign draft. They require an exact
immutable effect preview, idempotency, current authorization and a separate
15-minute explicit confirmation by the same signed-in Brand user unless the
user instead granted the dedicated, revocable campaign-execution scope. Generic
OAuth consent or adoption of a safe draft does not authorize either action.
For paid publication, funds already received by Influblog must be reserved in
the Brand wallet before public visibility. A separate wallet-spend scope can
use only available wallet funds; missing funds return a secure top-up action.
The agent cannot access card data, bypass payment-provider verification, or
confirm a user-action-required wallet top-up.

See the public [Privacy policy](https://influblog.com/privacy) and
[Terms](https://influblog.com/terms) for the current public policies.
