Security

Last updated: September 2026

This page explains how PleaseRepost handles authentication, data storage, and employee privacy. If your security team needs additional documentation, contact us at security@pleaserepost.com.

🔒

Encryption in transit

All traffic is served over HTTPS via AWS CloudFront with a TLS certificate managed by AWS Certificate Manager. Unencrypted HTTP is not accepted.

🗄️

Data storage

Company and employee data is stored in a database on AWS EC2 infrastructure in the us-east-1 region. Daily encrypted backups are stored in AWS S3 with a 30-day retention policy.

🛡️

No employee passwords

Employees never create passwords in PleaseRepost. Authentication is handled entirely through LinkedIn's official OAuth flow. We do not store LinkedIn passwords or long-lived tokens.

Employee-initiated actions

Reposting is never a silent background action. Each repost requires the employee to click "Repost" and complete a fresh LinkedIn OAuth authorization. Employees are always in control.

🏢

Corporate SSO

Administrators can require co-admins to sign in with Microsoft Entra ID or Okta instead of LinkedIn, ensuring access is governed by your existing identity provider and offboarding policies.

📋

Data minimization

PleaseRepost collects only what is needed to deliver the service: company name, employee names and emails, LinkedIn profile IDs, and reshare activity. No behavioral tracking or ad targeting.

Administrator authentication

Break-glass login

The primary administrator account uses a password-protected break-glass login that is locked by default. It is intended only for initial setup and emergency access, not for day-to-day use. The initial break-glass window is valid for 72 hours only. Any subsequent access must be specifically requested from the PleaseRepost technical team, which opens a 24-hour window and notifies your designated security contacts by email with the timestamp and IP address of the access event.

Co-administrator SSO

Ongoing administrator access is handled through co-administrator accounts linked to your corporate identity provider. PleaseRepost supports:

  • Microsoft Entra ID — co-admins sign in with their Microsoft work account via OIDC
  • Okta — co-admins sign in with their Okta account via OIDC
  • LinkedIn OAuth — available for organizations that do not use a corporate IdP

When SSO is configured for an organization, the LinkedIn login path is blocked — co-admins who attempt to sign in with LinkedIn are shown an error directing them to the correct SSO path. Access is revoked immediately when the co-admin is removed from the dashboard.

Employee authentication & LinkedIn access

Employees receive a personal permanent link to their repost page. When they click "Repost via LinkedIn," they are redirected to LinkedIn's official OAuth authorization flow. PleaseRepost:

  • Does not ask employees for their LinkedIn password
  • Does not store LinkedIn passwords
  • Requests only the permissions required to post a reshare on the employee's behalf
  • Does not perform any LinkedIn actions without the employee initiating them

Employees can revoke PleaseRepost's LinkedIn access at any time through their LinkedIn account settings under Permitted Services. Admins can also regenerate or remove an employee's personal link at any time, immediately revoking their ability to reshare.

Access control

Access to company data is scoped by organization. Administrators can only see and manage data for their own company. Co-administrators have the same dashboard access as the primary administrator, with the exception of managing other co-admins and configuring break-glass contacts — those actions are restricted to the primary administrator only.

Infrastructure

PleaseRepost runs on AWS infrastructure in the us-east-1 (Northern Virginia) region:

  • Compute: AWS EC2 with IAM role-based access — no long-lived access keys on the instance
  • CDN: AWS CloudFront for all web traffic, with HTTPS enforced
  • Backups: Daily database backups to AWS S3, retained for 30 days, with automatic expiry
  • Email: AWS Simple Email Service (SES) for transactional notifications only

Optional integrations

Slack and Microsoft Teams integrations are optional. If configured, PleaseRepost sends a weekly reshare summary to the webhook URL the administrator provides. No employee data beyond aggregate participation counts is included in these notifications. PleaseRepost does not initiate any other outbound connections to third-party services on your behalf.

Data retention & deletion

Company data is retained for as long as the account is active. If you close your account, contact us at security@pleaserepost.com to request deletion of all associated data. Backups containing your data expire automatically after 30 days.

Certifications

PleaseRepost does not currently hold SOC 2, ISO 27001, or other third-party security certifications. If your organization requires certified vendors, contact us to discuss your requirements.

Security inquiries

To request additional security documentation, report a vulnerability, or discuss your organization's security requirements, contact us at security@pleaserepost.com. We aim to respond to all security inquiries within one business day.

Consent Preferences