Security

Security and account access controls

CommentProtect is designed so your team can moderate at scale without sharing Meta credentials. Here is how connections, access, and your data are handled.

Moderator

Moderators have full access to comments, but they do not have access to moderation settings or account settings.

CommentProtect
CommentProtect
Acme Corp
Acme Corp
Controls

How access is protected

Official Meta OAuth

Connect with Meta OAuth and the Graph API. CommentProtect never asks for or stores your Facebook or Instagram password.

Encrypted access tokens

Meta access tokens are stored encrypted and used only to perform the actions you configure on connected accounts.

Role-based access

Owners, admins, managers, and moderators get scoped permissions, so people only do what their role allows.

Per-Page assignments

Assign teammates, VAs, and clients to specific Pages so they never see accounts they shouldn't.

Security headers

Responses ship a strict security header policy, including a content security policy, to harden the app in the browser.

Revoke any time

You can revoke CommentProtect's access from Meta at any time, and account deletion is available through the GDPR portal.

Data handling

What we process and how

What we process

CommentProtect processes new comments, replies, and related moderation metadata on connected Pages and Instagram Business Accounts after connection. Direct-message and Messenger inbox conversations are not processed in the current launch, and historical comment import is not available.

Where access is scoped

Each teammate authenticates with their own login. Access is limited by role and by Page assignment, with no shared Meta credentials.

Your data rights

Access, export, and deletion requests are handled through the GDPR portal. Deletion requests are verified by email and processed by the deletion worker within the configured SLA.

FAQ

Security questions

Do you store my Facebook or Instagram password?

No. CommentProtect connects through official Meta OAuth and the Graph API. We never receive, request, or store your Meta password. Access is granted by token, which you can revoke from Meta at any time.

Can team members access accounts they shouldn't?

No. Access is controlled by role and by per-Page assignment. A moderator assigned to one client's Pages cannot see another client's Pages, and only owners and admins manage connections and billing.

How do I delete my data?

Use the GDPR portal to request export or deletion. Deletion is verified by email, scheduled within the configured deletion SLA, and carried out by the deletion worker.

Are you SOC 2 or HIPAA certified?

CommentProtect is built on Meta OAuth, encrypted token storage, role-based access, and strict security headers. We do not claim formal certifications such as SOC 2, HIPAA, or SSO on this page; contact support for the current status of any specific compliance requirement.

Moderate safely, without sharing logins

Connect through Meta OAuth and give your team scoped access in minutes.