Security Policy — Newster (newster.net)


Effective Date: September 13, 2026


1. Executive Summary & Commitment


At Newster (operated via newster.net), security is foundational to our mission of providing a reliable, seamless, and automated social media management platform. As an auto-posting service that connects directly to your valuable social media accounts, we prioritize protecting your data, API tokens, content, and personal credentials.

This Security Policy outlines the technical, organizational, and administrative controls implemented by Newster to safeguard our infrastructure, maintain platform availability, and ensure strict data privacy across all social media integrations.



2. Infrastructure & Network Security


Newster leverages industry-leading cloud service providers to maintain a resilient, secure, and scalable hosting environment.

  • Data Center Security: Our infrastructure is hosted in top-tier, compliant data centers featuring 24/7/365 physical security, biometric access controls, video surveillance, and redundant power and cooling systems.

  • Network Defense & Firewalls: We utilize Web Application Firewalls (WAF) and distributed denial-of-service (DDoS) mitigation services to filter malicious traffic, prevent intrusion attempts, and mitigate volumetric attacks.

  • Network Isolation: Platform services and database layers operate within isolated Virtual Private Clouds (VPC) with restricted subnetting and strict Security Group / Network Access Control List (NACL) configurations.



3. Data Encryption & Storage


We employ enterprise-grade encryption standard practices across all lifecycle stages of your data.


3.1 Encryption in Transit


All traffic between users, Newster servers, and third-party social media APIs (e.g., Facebook, X/Twitter, LinkedIn, Instagram, Pinterest, TikTok) is encrypted using TLS 1.3 (with TLS 1.2 as a minimum threshold) over HTTPS. Plaintext HTTP traffic is automatically redirected to secure HTTPS endpoints.


3.2 Encryption at Rest


  • Database & Backups: Sensitive data stored in our primary databases and backup storage is encrypted using AES-256 encryption.

  • OAuth Tokens & Credentials: Access tokens, refresh tokens, and API credentials connected to your social media accounts are encrypted at the field level before being committed to persistent storage. Newster never stores your raw social media account passwords.


4. Authentication & Access Control


4.1 Social Media Account Authentication


Newster utilizes an official OAuth 2.0 protocol implementation for connecting third-party social media channels.

  • We request only the minimal necessary permissions required to execute post automation, scheduling, and analytics.

  • You can revoke Newster’s access to any social media profile at any time directly through the respective platform's security settings or within the Newster platform dashboard.


4.2 User Account Security


  • Password Hashing: User account passwords are stored using salted key-stretching algorithms (such as bcrypt/Argon2). Passwords are never stored or logged in plain text.

  • Session Management: User sessions employ secure HttpOnly, SameSite cookies with restricted lifetimes to prevent session hijacking and Cross-Site Scripting (XSS) exploitation.


4.3 Internal Access Controls

  • Principle of Least Privilege (PoLP): Access to production environments, user data, and system configurations is strictly restricted to authorized Newster personnel whose job duties explicitly require it.

  • Multi-Factor Authentication (MFA): All administrative and development access to Newster infrastructure requires mandatory Multi-Factor Authentication and hardware-backed or time-based one-time password (TOTP) verification.


5. Application & Code Security


Newster embeds security checks directly into the software development life cycle (SDLC).

  • Vulnerability Scanning & Management: Software dependencies and third-party libraries are continually scanned for known vulnerabilities (CVEs) and automatically updated.

  • Secure Coding Standards: Our development team adheres to OWASP (Open Web Application Security Project) guidelines to guard against common web vulnerabilities, including SQL Injection (SQLi), Cross-Site Request Forgery (CSRF), and Remote Code Execution (RCE).

  • Automated & Manual Testing: We conduct routine code reviews, static application security testing (SAST), and dynamic application security testing (DAST) prior to deploying updates to production.



6. Operational Resilience & Disaster Recovery


  • Automated Backups: System data and configuration states are backed up automatically on a continuous schedule. Backups are encrypted and stored across geographically separated regions to prevent single-point data loss.

  • Business Continuity: Newster maintains an active Disaster Recovery (DR) plan designed to achieve rapid Recovery Point Objectives (RPO) and Recovery Time Objectives (RTO) in the event of an infrastructure outage or regional disaster.

  • Uptime & System Monitoring: Automated health checks and performance monitoring run continuously. System anomalies or unexpected downtime trigger real-time alerts to our technical operations team.



7. Media & Upload Safety


Because Newster processes user-uploaded media (images, videos, documents) for scheduled publishing:

  • All incoming files undergo automated scanning to detect and quarantine malware, executable payload risks, or corrupted file formats prior to storage and processing.

  • Media assets are stored on dedicated, private media servers configured with strict access restrictions.



8. Responsible Disclosure & Vulnerability Reporting


We welcome input from security researchers and the global community to help keep Newster and our users safe.

If you believe you have identified a potential security vulnerability within newster.net or its API endpoints, please notify us immediately.



Guidelines for Vulnerability Reporting:


  1. Email your findings directly to admin@newster.net.

  2. Provide sufficient details to reproduce the issue (including steps, screenshots, or proof-of-concept scripts).

  3. Do not access, alter, or delete data belonging to other users.

  4. Give us a reasonable timeframe to review and remediate the issue prior to making any public disclosure.

We commit to acknowledging receipt of your report within 48 business hours and keeping you informed as we address the issue.



9. Contact & Governance


For questions regarding this Security Policy, account protection mechanisms, or general data handling practices, reach out to our security team:

  • Website: https://newster.net

  • Security Contact Email: admin@newster.net

  • General Support: support@newster.net

We may use cookies or any other tracking technologies when you visit our website, including any other media form, mobile website, or mobile application related or connected to help customize the Site and improve your experience. learn more

Allow