Security and trust
Wonder Publisher AI Security
Last updated: 7 August 2026
Security overview
Wonder Publisher AI is designed as a desktop application with account-specific workspaces and cloud-assisted OAuth authorization. The security model aims to keep provider passwords out of the application, keep sensitive credentials outside the renderer, and ensure publishing actions use the exact destination selected by the user.
1. Security architecture
- Official OAuth authorization pages are used for supported providers.
- Provider client secrets remain in controlled server-side configuration.
- OAuth handoff uses signed state, expiry checks, provider checks, loopback callback validation, and encrypted desktop delivery.
- Electron renderer privileges are restricted through context isolation, disabled Node integration, sandboxing, and a typed preload bridge.
- External URLs are validated and opened through the system browser.
2. Credential protection
- Access tokens, refresh tokens, Page tokens, and user AI keys are treated as secrets.
- Secrets are stored using operating-system-backed secure storage when available.
- The application is designed not to fall back to plaintext credential storage.
- Tokens are never intentionally exposed to the renderer, publishing history, or exported diagnostics.
- Logs redact common secret fields and token-like values.
3. Account and publishing isolation
Publishing credentials are resolved by provider and stable account or asset ID. Facebook Page publishing uses the token belonging to the selected Page; TikTok publishing uses the selected TikTok account token; YouTube channels use the owning Google identity; Instagram publishing uses the linked Facebook Page authorization context.
Queued and scheduled jobs retain their exact destination. A stale or disconnected destination is blocked rather than silently replaced.
4. Filesystem safety
- Access is limited to user-selected files and configured workspace folders.
- External files are not deleted when copied into a workspace.
- Paths, file types, existence, size, readability, and destination writability are validated.
- Workspace operations use bounded actions rather than arbitrary renderer filesystem access.
5. Diagnostics and logging
Production logs are structured, size-limited, and redacted. A diagnostic export may contain app version, operating system, sanitized errors, capability states, and workflow status. It must not contain provider passwords, complete tokens, private keys, authorization codes, temporary upload URLs, or user video files.
6. Dependencies and updates
Dependencies are reviewed using type checking, linting, automated tests, production builds, and security-audit reports. Signed installers and signed update delivery are recommended for commercial distribution. The application must not silently install untrusted or unsigned updates.
7. User security responsibilities
- Use a secure device and operating-system account.
- Review the selected destination before publishing.
- Protect local workspace folders and exported diagnostics.
- Revoke provider access after suspected account compromise.
- Keep Wonder Publisher AI updated.
8. Report a vulnerability
Email support@rosanix.com with a clear description, affected version, reproduction steps, and impact. Do not include active credentials or publish sensitive details publicly before Rosanix has had a reasonable opportunity to investigate.
9. Security limitations
No software, device, network, or third-party API can be guaranteed completely secure. Provider outages, compromised user accounts, malware on a user’s device, or platform-side policy changes are outside Rosanix’s full control.