Trust / public evidence

Know who holds the keys and what happens when an agent acts.

OpenPMM publishes to accounts you care about. This page records the operator, credential boundary, human checkpoints, API behavior, and data-handling scope behind that access.

An accountable operator

OpenPMM is built and operated by Heyora UG (haftungsbeschränkt), a registered German company. The public imprint names the company, managing director, Berlin address, commercial register number, VAT ID, and contact address.

Credentials stay inside their intended boundary

A CLI-managed agent works through the openpmm command and never reads its credential store. A direct API client uses a separate scoped credential. Provider OAuth tokens stay server-side and are not returned in Post content, CLI output, webhook payloads, or the writing context.

Public publishing remains an explicit side effect

An agent can prepare text, media, a Destination, and timing. Publishing and scheduling require an explicit confirmation value. OAuth also remains a browser checkpoint. This keeps the person responsible for the account in the loop when access is granted or content reaches an audience.

Retry-safe API behavior is documented

A publish response means that OpenPMM accepted or completed the state change. It does not always mean that the provider finished. OpenPMM documents bounded CLI waiting, Post state, receipts, idempotency keys, ETags, stable errors, and request IDs.

Webhook deliveries can be verified

Workspace webhooks sign Post events with an endpoint secret. OpenPMM documents payload verification, endpoint testing, delivery inspection, and secret rotation. The previous secret remains valid during a documented overlap when a secret is rotated.

Data handling is described by purpose and provider

The privacy policy describes account, publishing, provider, analytics, feedback, and website processing separately. It names relevant processors and transfer safeguards. OpenPMM does not describe all processing as EU-only because publishing necessarily sends content to the social providers a user selects.

Use the evidence

Evaluate the publishing path before you connect an account.