Security & Trust
Dual.am connects to social networks using their official APIs and authorization systems. We never ask for or store your Facebook, Instagram, LinkedIn or TikTok passwords.
Authorization tokens are encrypted at rest and only decrypted when required to publish content you scheduled.
Dual.am is operated by Turn LLC, a registered Armenian technology company founded by Rafayel Tobelyan.
We never see or store your social account passwords — only the token you authorize.
Tokens, bot credentials, and 2FA secrets are encrypted in the database.
Each brand or client is walled off from every other workspace on Dual.am.
Dual.am integrations use the official APIs and authorization flows provided by each supported platform. You connect an account by signing in on the platform's own site and approving the permissions there — the login form is theirs, not ours, and your password is never typed into Dual.am.
We request only the permissions publishing actually requires: the ability to post to the Pages, profiles, or channels you selected. We do not request or use permissions to read your inbox, message your contacts, or profile your audience.
Meta operates an App Review process to verify that apps use its APIs and products in approved ways, and TikTok likewise requires apps using its developer tools to go through review.
Telegram is the one exception to OAuth, because Telegram has no OAuth flow for bots: you create a bot in Telegram yourself and paste its bot token into Dual.am. That token belongs to a bot you own — never to your personal Telegram account — and you can revoke it from Telegram at any time.
You can revoke Dual.am's access from inside any platform's own app settings at any time, independently of anything you do in Dual.am.
In transit: the entire application is served over HTTPS. Traffic between your browser and Dual.am, and between Dual.am and every platform API, is encrypted in transit.
At rest: OAuth access tokens, refresh tokens, Telegram bot tokens, two-factor secrets, and two-factor recovery codes are stored encrypted using AES-256 with an authenticated encryption scheme, so a modified ciphertext is rejected rather than decrypted. The encryption key lives in the server environment, never in the database and never in our source code.
Account passwords are never stored in any reversible form — they are hashed with bcrypt. Nobody at Dual.am, including us, can read your Dual.am password.
Every connected account, post, and schedule belongs to exactly one workspace. Isolation is enforced at the database query layer — every query for workspace-owned data is automatically constrained to the workspace you are currently working in, rather than relying on each screen to remember to filter correctly.
This applies between your own workspaces too, not just between different customers. If you run one workspace per client, content and credentials in one client's workspace are not visible from another.
Within a workspace, teammates you invite hold explicit roles, and actions like managing connections, managing members, and transferring ownership are permission-checked on the server for every request — not just hidden in the interface.
Deleting your Dual.am account does not delete anything already published to a social network — those posts live on the platform and are managed there.
The production database is backed up on a regular automated schedule, and backups are stored separately from the server that produced them, so losing the application server does not mean losing your data. Backups are subject to the same access restrictions as production: only the operators listed under Access control can reach them.
Because your credentials are encrypted before they are written to the database, they remain encrypted inside every backup as well — a backup on its own does not reveal a single usable token.
Dual.am is run by a small team, which means the list of people who can reach production is short and known by name. Access is granted on a need-to-operate basis and removed when it is no longer needed.
You can turn on two-factor authentication for your own Dual.am account from your Profile page. It works with Google Authenticator and any other standard TOTP app — scan the QR code, confirm one code, and every future sign-in asks for a six-digit code as well as your password. You also get one-time recovery codes in case you lose your phone, and you can regenerate them at any time.
If you manage client accounts on Dual.am, turning this on is the single highest-value thing you can do to protect them.
If we detect or are told about a security incident, our order of operations is: contain it, assess exactly what was affected, fix the underlying cause, and then tell the people whose data was involved.
If you believe you have found a security vulnerability in Dual.am, please tell us before you tell anyone else. Email [email protected] (or [email protected]) with enough detail to reproduce the issue — a URL, the steps you took, and what you observed.
We do not currently run a paid bug bounty, but we are glad to credit you publicly if you would like that.
Dual.am is developed and operated by Turn LLC, an Armenian technology company founded by Rafayel Tobelyan.
Turn LLC also operates Turn.am, one of Armenia's biggest service discovery platforms. Dual.am is not a side project of an anonymous team — it is run by a registered company with a public track record and a name attached to it.
Legal entity
Turn LLC
For anything else — questions about this page, a data request, or a security concern — email [email protected]. The formal terms are in our Privacy Policy and Terms of Service.
If something on this page isn't clear enough to trust us with a client account, tell us — we'll answer plainly.