Workspace access is checked on the server
Application operations check workspace membership and the role required for the action. Source approval, asset approval and final publication approval are separate decisions. Public website support requests have a separate platform-administrator inbox; a customer workspace owner cannot read another person's public enquiry.
Credentials stay out of the creative workflow
Integration credentials are encrypted on the server. Private media uses an authenticated storage path. Customers authorize their own connected accounts through the provider flow rather than entering EvokeLoop's platform secret. Never send an access token or password through a support form.
Reviews apply to the actual version
Changing creative or destination details invalidates the relevant approval. The publishing worker rechecks authorization and approved assets before delivery. Test schedules do not become live merely because live delivery is later enabled, and uncertain final delivery results are not retried blindly.
No implied certification or platform approval
This page describes implemented controls, not a SOC 2, ISO 27001, GDPR-compliance or Meta-partner certification. Public Meta access, live-account compatibility and policy review remain separate readiness requirements. No system is risk-free, and external providers can change access or functionality.
Report a concern
Use Contact with the Support or Privacy topic. Describe the affected feature and how to reproduce the concern without including credentials or other people's data. The platform team reviews submitted requests. Do not test security issues against customer information or disrupt the service.