Platform Integration & Security Disclosures

Integrations & Platform Access

Agents Kart connects to external platforms like X, LinkedIn, GitHub, and your document storage only with your explicit permission. Below, we explain exactly what each agent can see and do once connected โ€” and what we never do with your data.

Encryption
AES-256-GCM
Tokens encrypted at rest
OAuth 2.0 PKCE
Scoped Access
Minimal scopes requested
Web Scraping
Transient Only
In-memory processing
Zero Resale
Private & Isolated
No 3rd-party data selling

Verified Integration Credentials

Official developer registrations, granted products & verified platform dashboards

Agents Kart integrates directly with official developer APIs. Below are our verified developer application credentials and developer portal dashboard listings.

in
LinkedIn Developer App
Verified
Granted Products:Share on LinkedIn
OAuth Protocol:OAuth 2.0 Authorization
Requested Scope:w_member_social
๐•
X Developer App
Verified
API Access Level:Paid Official API (Read + Write)
OAuth Protocol:OAuth 2.0 PKCE
Granted Scopes:tweet.read, tweet.write
Developer Portal Dashboard Listings
LinkedIn Developer App Listing
LinkedIn Developer Portal Listing Screenshot
Click to expand screenshot
Shows verified app status and granted 'Share on LinkedIn' product permissions.
X Developer App Listing
X Developer Portal Listing Screenshot
Click to expand screenshot
Shows official project dashboard with granted Read and Write API access.
in
Official Agents Kart LinkedIn Company Page
Connected via LinkedIn's Official API
View Public Page

LinkedIn Post Automation Agent

Publishes user-approved content to LinkedIn

OAuth 2.0
What it Reads

Nothing beyond basic profile confirmation required to construct a post. No access to your feed, connection lists, profile messages, or inbox.

What it Writes

Posts, articles, and media updates that you have specifically configured or pre-approved within your agent workflow.

Technical Specs
Access Scope:w_member_social
Scope Limitation:Post on your behalf only
Token Security:AES-256-GCM Encrypted
Revocation:Access can be revoked anytime from LinkedIn Settings > Data Privacy > Permitted Services, or via your Agents Kart configuration panel.
๐•

X (Twitter) Post Automation Agent

Posts, threads, and optional comment auto-reply

OAuth 2.0 PKCE
What it Reads

Comment activity on your own posts only (if Auto Reply add-on is enabled by you โ€” off by default). No access to your DMs, home timeline, or follower list.

What it Writes

Posts, threads, and automated comment replies that you have explicitly enabled or configured.

Technical Specs
API Tier Level:Paid Official API (Read + Write)
Granted Scopes:tweet.read, tweet.write, users.read, media.write
Auto Reply State:Off by Default (User Toggled)
Token Security: OAuth 2.0 PKCE flow tokens are encrypted at rest using AES-256-GCM and never shared with third parties.

Resume Screener Agent

Analyzes candidate resumes & public profile links

Read-Only / No Account OAuth
External Access

Read-only public web lookups for GitHub profiles, portfolio websites, or live deployed application URLs explicitly listed on candidate resumes.

No account connections or write access to candidate platforms.
Data Handling & Retention

Uploaded resumes (PDF/DOCX) are stored in Cloudflare R2 in encrypted storage strictly to provide evaluation reports, isolated per organization.

Resumes are never sold, rented, or shared with third parties.

Market Research Agent

Public web research on target industries & competitors

Transient Scraping
External Access

Read-only crawling of publicly available competitor websites, public pricing pages, news announcements, and customer reviews.

Data Handling & Retention

Scraped pages are processed transiently in memory to synthesize the report. Raw HTML and scraped web content are never saved or stored in our database.

Knowledge Library Agent

Private GraphRAG knowledge base & document indexing

Isolated per Org
Ingestion & Sync

Ingests uploaded organization documents or optional external sources (Jira/Confluence/Google Drive) authorized by explicit OAuth.

Read-Only Sync

Never writes back or modifies your connected third-party document systems.

Internal Visibility Scoping

Documents are retained in Cloudflare R2 and PostgreSQL (`pgvector`) with strict per-organization data isolation and multi-tier role permissions:

ALL: Visible to all org membersENGINEERING: Scoped to tech rolesLEADERSHIP: Scoped to admins

Data & Security Summary

Complete security standards for platform access & data handling

Tokens Encrypted at Rest

OAuth access and refresh tokens for connected platforms are encrypted at the application level using AES-256-GCM with unique initialization vectors before being saved to PostgreSQL. Tokens are never logged or exposed in client responses.

Transient Scraping Policy

Scraped web pages (e.g. competitor research) are processed transiently in memory during execution. Raw HTML files and web page contents are discarded immediately after report generation.

Data Isolation & Zero Third-Party Resale

Uploaded files and knowledge bases are isolated strictly per organization. No user data is ever sold, rented, or shared with third parties.

Immediate Access Revocation

Users can disconnect any integration at any time from their Agents Kart configuration dashboard, which immediately revokes our access token and halts all agent automated tasks.

Questions about security or integrations?
Our team is available to assist with custom compliance needs.
Contact Support