Security

Last updated 26 September 2026

Connected accounts

The access platforms give Postmaxx is stored encrypted and used only to do what you ask, such as publishing your posts. Postmaxx never asks for a platform’s main password, and you can disconnect an account at any time.

Sign-in

You sign in with a one-time code sent to your email, or with Google, so there is no Postmaxx password to leak or reuse. Sign out of other devices in Settings ends your other sessions at once.

Team roles and keys

Each workspace has an owner, admins and members, and each role can do only what it needs. An API key is shown once, and you can revoke any key in Integrations.

Connections

Postmaxx is served only over HTTPS.

Payments

Card details are entered on Stripe’s pages and kept by Stripe. Postmaxx never sees or stores card numbers.

Report a vulnerability

Email postmaxx@support.eniva.io with the steps to reproduce what you found. Please don’t access other people’s data, slow the service down, or share the problem publicly before we fix it. We reply within 2 business days.

Postmaxx is run by Eniva LLC, Delaware, USA.