Security and trust

Clear facts about how your connections are handled.

This page explains controls that exist today. It does not claim a certification, audit opinion, uninterrupted availability, or an absolute security guarantee.

Encrypted connected-account tokens

OAuth tokens stored by ApexStream are encrypted at rest with AES-256-GCM. They are used to provide the connected broadcasting feature you authorize.

Connections stay under your control

You can disconnect an integration from the dashboard. When the final YouTube channel for a connected Google account is removed, ApexStream deletes its local token copies and requests revocation from Google.

Sensitive stream details are treated as credentials

Stream keys and account tokens are not shown as public profile information. Use the dashboard to replace or disconnect them when a platform rotates access.

Point-in-time service checks

The service-health page reports the current result of a core API check. It is not an uptime history, service-level promise, or a statement about third-party platforms.