Your Credentials Are Encrypted. Even We Can't See Them.

How SocialsPro protects your bot tokens, WordPress passwords and Soroush Plus sessions — and why not even our own admins can read them.

Posted September 23, 2026 by the Socials Pro Team


When you connect an account to SocialsPro, you're trusting us with something sensitive. A Telegram bot token. An Eitaa API key. A Soroush Plus session. Your WordPress password.

That trust deserves real protection — not just promises.

Today, we're publishing what we've built to protect it.


What We Protect You From

Here's the honest truth about running a platform like SocialsPro: the server that stores your credentials is a target.

If someone breaks into our server — or steals a backup, or finds an old database copy — they could potentially access everything.

So we built our systems assuming that will eventually happen. Here's what that means for your credentials:

  • If our database is stolen, the thief finds only encrypted gibberish.
  • If a backup leaks, nothing in it can be used to access your accounts.
  • If a server is compromised, your credentials stay secret.
  • If someone with admin access tries to abuse their position, they can't. The system prevents it.

Not "we'll try to stop them." They can't.


How We Protect Your Bot Tokens

When you connect Telegram, Eitaa, Bale, or Rubika to SocialsPro, you provide a bot token. That token lets our system post to your channels on your behalf.

Here's what happens to it the moment you click Connect:

  1. It's encrypted immediately using AES-256-GCM — an industry-standard encryption algorithm used by banks and governments.
  2. The encryption key lives outside the database. It's stored in a secure location that only the running application can access. It's never written to disk alongside your data.
  3. Each token is bound to your specific account. Even if someone tried to copy a token from one account to another, the encryption would fail. The tokens are locked to their owners.
  4. It's decrypted only at the exact moment of use — when our system is about to send a post on your behalf. Once the post is sent, the decrypted value is cleared from memory.
  5. It's never logged. Ever. Not at debug level, not in error messages, not in audit logs. Never.

If someone breaks into our server and reads the database, they see this:

enc:v1:Aa7Bx9KmPq3fN2vRz...

That's it. No token. No channel ID. No way to post as you.


How We Protect Your Soroush Plus Account

Soroush Plus is different from the other platforms. Connecting it doesn't just give us permission to post — it stores a session file that represents a full login to your Soroush account. That's a much more sensitive credential.

Here's how we protect it:

  • The session file is encrypted using the same AES-256-GCM algorithm.
  • When our system needs to use it, the session is decrypted only into memory — never to disk.
  • After use, the memory copy is shredded. The session file on disk is always encrypted.
  • The decrypted session never touches the filesystem. Even a snapshot of the server's disk shows only encrypted blobs.

If our server is stolen, the thief gets encrypted session files that are useless without the key.


Why Even Our Admins Can't See Your Data

This is the part we're most proud of.

Most platforms — even reputable ones — give administrators the ability to access user accounts. Sometimes for support, sometimes for investigation. It's a common design. We don't do it.

Here's what our admins can and cannot see:

What Admins Can SeeWhat Admins Cannot See
That you connected a Telegram botYour Telegram bot token
The label you gave the accountThe actual credential
Whether your account is activeYour WordPress password
How many posts you've sentYour Soroush session
Whether your account is failingAny decrypted credential, ever

Admins can help you — "your Telegram account seems disconnected, try reconnecting" — without seeing the credential itself.

An admin cannot log in as you. An admin cannot post as your bot. An admin cannot read your messages.

We didn't build "admin access" and then restrict it. We built a system where admin access doesn't exist for these credentials.


How We Enforce It

Encryption is not optional at SocialsPro. It's enforced at the code level.

  • There is no plaintext fallback. If the encryption key is missing, the application refuses to start. There is no "development mode" that skips encryption.
  • There is no admin bypass. No endpoint exists that returns decrypted credentials to a human.
  • There is no debug path. Even during troubleshooting, credentials stay encrypted.
  • Every admin action is logged. If an admin performs a sensitive action — password reset, tier change, account suspension — it's recorded in an audit log we review monthly.

The system is designed so that even if we wanted to bypass these protections, we couldn't easily do so — and every attempt would leave a trail.


What This Means for You

If you're a channel admin

Your bot tokens are safe. If our server were ever compromised, your channels would be unaffected. Nobody could post as your bot or read your inbox.

If you're a photographer

Your Soroush Plus session is encrypted. Your client galleries and client data are protected. Even if a backup leaked, the session couldn't be reused to access your account.

If you're a business

You can tell your clients, with confidence: "The tool we use encrypts every credential and even the platform's own team cannot access our accounts." That's not a marketing line. It's how the system is built.


What We Ask of You

Security is a partnership. Here are three things you can do to protect yourself further:

  1. Rotate your bot tokens periodically — every 6 months is a good habit.
    • Telegram: Open @BotFather, send /revoke
    • Eitaa: Log in to eitaayar.ir and issue a new token
    • Bale: Contact their support to request a new token
  2. Use a dedicated bot for SocialsPro. Don't reuse a bot token across other services. If that token is compromised elsewhere, it stays elsewhere.
  3. Never share your bot tokens or session credentials with anyone — including our support team. If someone asks you for a credential, they're not us.

Our Ongoing Commitment

Security isn't a project that ends. Here's what we're doing on an ongoing basis:

  • Encryption keys are rotated annually.
  • Admin actions are audited monthly.
  • Security reviews happen quarterly.
  • Users are notified within 72 hours if any incident affects their data — even if we're not legally required to disclose it.
  • We publish an annual security summary. What we've protected, what we've audited, what's next.

We don't have a marketing budget for "trust." We have a technical one.


Why We're Publishing This

Iranian users deserve to know how their data is handled.

Most platforms don't talk about security until something breaks. We think that's backwards. If we're asking you to trust us with your channels and your content, we owe you a clear explanation of how we protect them.

If you're using a different Iranian platform for your content, ask them: "How do you store my credentials? Can your admins see them?"

If they can't answer clearly, that's your answer.


If You Have Questions

If you want to know more about how SocialsPro protects your data, email us at admin@socialspro.ir.

We're happy to explain any part of our security architecture.


— The SocialsPro Team
Power of Narrative

securityencryptioncredentials

Turn your channels into a system

Plan, schedule and publish across Telegram, Eitaa, Bale, Rubika, YouTube and more — from one place.

Start free trial