SECURITY

Security

MindThread manages your Threads accounts on your behalf. We understand the importance of account security. Here's how we protect your data and credentials.

Transport Encryption

  • All connections enforced with HTTPS/TLS encryption
  • Data in transit between browser and server is fully encrypted
  • Plain HTTP connections are not supported

Infrastructure

  • Database on Google Firebase Firestore (Google Cloud infrastructure)
  • Frontend deployed on Vercel (global CDN + DDoS protection)
  • Server-side code is not publicly accessible

Token Management

  • Threads Access Tokens stored in a protected server environment
  • Tokens auto-refresh every 60 days to ensure uninterrupted authorization
  • Tokens are immediately purged upon expiry or account removal
  • We never store your Threads password

Account Isolation

  • Each user can only access their own account data
  • All account APIs require authentication; there is no unauthenticated access
  • API responses never contain other users' tokens or keys

API Security

  • The official-API line (scheduling, auto-replies on your own posts, analytics) uses only Meta's official Threads Graph API
  • The official-API line uses no unofficial or undocumented Threads endpoints
  • All official API requests include valid OAuth 2.0 credentials

Access Control

  • Admin panel requires Firebase Authentication
  • Admin functions have independent isAdmin dual verification
  • Sensitive operation paths have input boundary validation to prevent path traversal attacks

Patrol (Taiwan customers only, optional, a separate line)

  • Browser patrol runs as an extension in your own browser, does not go through Meta's official API, and sits in a grey area of the platform terms; the account carries risk
  • Patrol is optional, off by default and can be turned off anytime; the official-API statements above do not cover browser patrol
  • We do not claim patrol has zero ban risk; see the patrol page (mindthread.tw/haixun) for the full disclosure

AI Auto-Reply Security

Auto-reply has 5 built-in security layers to prevent malicious comments from manipulating AI behavior (Prompt Injection attacks).

  1. Prompt Injection Detection: Analyzes comments for instruction override, role switching, system probing, and sensitive data extraction patterns. Covers English, Chinese, and Unicode variants.
  2. Input Sanitization: Removes control characters, truncates overly long inputs, ensuring raw comments enter the AI model in a safe format.
  3. Gemini Built-in Safety Filters: Enables Google Gemini's native safety review, blocking harassment, hate speech, sexual content, and dangerous content (BLOCK_MEDIUM_AND_ABOVE).
  4. Randomized Boundary Prompt Structure: Uses randomly generated boundary markers to isolate comments from instructions, preventing attackers from forging instruction boundaries.
  5. Output Validation: AI replies are reviewed before sending: length limits, no links allowed, no system information leakage (API Keys, Tokens, system prompts).

Blocked comments are logged with reasons and synced to the dashboard without affecting normal account operations.

What we never do

  • Never store your Threads password
  • Never share your tokens with any third party
  • Never post without your authorization
  • Never collect personal information beyond Threads
  • Never sell any user data
  • Never use unofficial Meta APIs in the official-API line (patrol is separate, see above)

Report a Security Issue

If you discover any security concerns or vulnerabilities, please contact us directly. We will respond within 48 hours. contact@ultralab.tw

Patrol and its risks · How it works · Privacy Policy