Security & account safety

Apisy does not automate LinkedIn. It writes content; you publish it. If you choose to connect an account, publishing happens through the platform's official API, using a permission that can do one thing: post on your behalf.

This page exists because "will this get my account banned?" is the right question to ask any tool in this category, and because you deserve a specific answer, not just a reassuring one. Everything below describes how Apisy actually works.

1. What Apisy connects to, and with what permission

Connecting an account is optional. Apisy works without connecting anything — you can write, plan and design, then copy and publish yourself. If you do connect, these are the exact permissions we request:

PlatformWhat we usePermission requested
LinkedIn Official LinkedIn REST API
/rest/posts, /rest/images
w_member_social — publish on your behalf
openid profile email — identify your account
X Official X API v2
/2/tweets, media upload
tweet.read tweet.write users.read media.write offline.access
Google Sign-in only (Google Identity Services) Your name and email address. Nothing else.

We never ask for your LinkedIn or X password. Authorization happens on the platform's own screen, and you can revoke it at any time from Apisy or from the platform's settings.

2. What Apisy cannot do

The list below is not a policy we promise to follow. It is a description of what the permissions above do not allow. Even if we wanted to, the access we hold could not do any of it:

  • Send connection invitations. No such capability exists in the permission we hold.
  • Send messages or DMs to anyone.
  • Like, comment or follow automatically on your behalf.
  • Scrape profiles, search results, or Sales Navigator.
  • Visit profiles or generate any activity you did not create.

And by architecture, Apisy also has:

  • No browser extension. Apisy is a web application — a PWA. Nothing is injected into your LinkedIn session. Browser extensions that operate inside your logged-in session are the single most common source of detection in this category.
  • No shared or residential proxies, and no IP rotation. Publishing calls go from our servers to the platform's official API, authenticated as you.
  • No password storage. We hold revocable API tokens, never credentials.

3. The five questions worth asking any tool

These are the questions security-minded buyers ask before connecting an account. Our answers:

  1. Official API or browser automation? Official API, for both LinkedIn and X. No automation of a browser session, ever.
  2. Dedicated or shared IPs? Neither, in the sense the question implies: there is no proxy layer. Calls originate from our own infrastructure and are authenticated with your own token.
  3. Are there configurable limits? You decide what gets published and when — nothing is sent that you did not create and schedule. See section 5 for the cadence we recommend.
  4. Is there human approval? Yes, by design. Apisy drafts; you review, edit and schedule. There is no mode in which Apisy acts on a platform without your instruction.
  5. Any history of restricted accounts? None to date. If that ever changes, we will say so on this page rather than wait to be asked.

4. Nothing is published that you did not approve

Apisy generates drafts. A post reaches LinkedIn or X only after you have reviewed it and scheduled it. There is no autopilot, no outreach sequence, and no background activity performed in your name.

5. Volume: our honest guidance

Apisy's 90-Day Calendar plans a sustainable cadence — roughly 2 posts a day on X and up to 4 a week on LinkedIn. You can add more whenever you like; we do not cap you, and every plan includes unlimited LinkedIn publishing.

We would rather be straight with you about why the recommendation exists. Posting far above that cadence is not what gets accounts restricted — the restrictions the industry reports come from automated connecting, mass messaging and scraping, none of which Apisy does. What excessive volume actually costs you is reach: audiences disengage, and the algorithm follows. The cadence we suggest is an audience recommendation, not a safety limit.

6. Your data

  • Access tokens are encrypted at rest in our database.
  • Disconnect at any time from your dashboard or from LinkedIn's or X's own settings, which revokes our access immediately.
  • Importing your analytics is optional. Apisy works without it; the export files you choose to upload power the tools that read your own data.
  • What we collect, how long we keep it and how to have it deleted is set out in our Privacy Policy.

7. Independence

Apisy is an independent product of Attentia LLC. It is not affiliated with, endorsed by, or sponsored by LinkedIn or X. Your use of those platforms remains governed by their own terms, and you are responsible for complying with them — see section 6 of our Terms of Service.

8. Reporting a security issue

If you find a vulnerability or something on this page that does not match what you observe, write to [email protected]. We would rather hear it from you than from someone else.

← Back to home