1. Security model
Bifro Connect is designed to reduce password sharing. Agencies and clients authenticate through Meta, review the requested access in Meta's interface, and keep their Facebook password and two-factor authentication codes with Meta.
Bifro stores the limited account, connection, asset, billing, and audit data needed to operate the service. Security controls are reviewed as the application changes, but no internet service can promise that incidents will never occur.
2. Authentication and permissions
- Agency and client Meta authentication occurs through Meta OAuth rather than a Bifro password form.
- Bifro requests access needed for the selected ads or social-media workflow and does not request Instagram inbox or direct-message access for the current flow.
- Sessions use HTTP-only cookies, SameSite protections, and secure cookies in HTTPS production environments.
- State-changing application requests are protected with request checks designed to reduce cross-site request forgery.
- Access can be revoked from Bifro or directly through Meta Business Settings.
Meta remains responsible for its authentication interface, account controls, permission review, and platform availability.
3. Encryption and sensitive data
Production traffic is sent over HTTPS. Meta access tokens stored by Bifro are encrypted at the application layer using authenticated AES-256-GCM encryption before being written to the database.
Encryption keys and service credentials are supplied through protected production environment configuration rather than embedded in public pages. Bifro does not store Facebook passwords, two-factor authentication codes, or complete payment-card numbers.
Stripe handles card entry and payment processing. Supabase provides the managed database infrastructure. More information about providers and cross-border processing is available in the Privacy Policy.
4. Application controls
Current application safeguards include:
- input validation and controlled database queries;
- security-focused HTTP headers and a content security policy;
- rate limiting on sensitive and high-volume endpoints;
- session expiration and server-side session storage;
- structured audit records for important account, connection, billing, and administrative events;
- restricted administrative access; and
- dependency and automated test checks before release.
Specific controls may change as threats, providers, and the application evolve. Public detail is intentionally limited where disclosure could weaken a control.
5. Monitoring, response, and deletion
Bifro records operational and security events needed to investigate failures, suspicious activity, billing problems, and access changes. Alerts are used for important service failures, and administrative tooling provides visibility into account and connection status.
When a deletion request reaches final processing, Bifro removes stored tokens, sessions, account data, and connection metadata that are not legally required. Failed external revocations are retried or escalated rather than silently treated as complete. Retention periods are listed in the Privacy Policy.
If Bifro determines that a breach of security safeguards creates a real risk of significant harm, Bifro will investigate, notify affected individuals and regulators as required, and preserve the legally required breach record.
6. Shared responsibility
Agencies and clients also play an important role. We recommend that you:
- enable multi-factor authentication on Meta and email accounts;
- send approval links only through trusted channels and only to authorized business administrators;
- request the minimum access needed and review active connections regularly;
- remove former team members from Meta and Bifro promptly;
- keep devices, browsers, and agency tools up to date; and
- report an unexpected approval, login, or connection immediately.
7. Infrastructure providers
Bifro depends on reputable service providers including Meta, Supabase, Stripe, Render, and an email delivery provider. Each provider secures the systems it operates under its own terms and security program. Bifro configures and uses those services but cannot guarantee their availability or security.
8. Report a security concern
Email info@bifro.ca with the subject Security Report. Include a clear description, the affected URL or account, steps to reproduce, and your contact details. Do not include passwords, access tokens, private client data, or complete card information.
Please act in good faith, avoid accessing data that is not yours, and give us reasonable time to investigate before public disclosure.
Bifro Tech Inc.Business Number 773892377 · Registry ID 18000166
34 Orwell Dr, Vaughan, ON L4H 4P7, Canada