{"status":"compliant","policyFramework":"Meta Commercial Developer Terms & TikTok Content API Guidelines","prohibitedMethodsDetected":{"headlessBrowserBots":false,"privateInstagramScraping":false,"automatedBulkDms":false,"fakeFollowerInjectors":false},"humanInTheLoopEnforced":true,"rulesCount":6,"rules":[{"id":"comp_1","featureName":"Creator Profile & Follower Metrics Discovery","category":"CREATOR_DISCOVERY","officialSupport":"NATIVE_OFFICIAL_API","metaEndpoint":"GET /{ig-user-id}?fields=business_discovery.username({target_username}){followers_count,media_count}","tikTokEndpoint":"GET /open_api/v1.3/creator/info/?creator_username={username}","policyGuideline":"Meta Business Discovery API allows verified Business Accounts to query public metrics of other Creator/Business accounts.","safeImplementation":"Queries only public business/creator statistics through verified App Tokens. Zero private scraping or headless cookies."},{"id":"comp_2","featureName":"Recent Public Posts & Engagement Review","category":"PUBLIC_CONTENT_REVIEW","officialSupport":"NATIVE_OFFICIAL_API","metaEndpoint":"GET /{ig-user-id}?fields=business_discovery.username({target}){media{id,caption,media_type,like_count,comments_count,timestamp,permalink}}","tikTokEndpoint":"GET /open_api/v1.3/video/list/?creator_username={username}","policyGuideline":"Permitted for commercial relationship management to audit publicly accessible media and verify brand alignment.","safeImplementation":"Fetches recent public media payloads to provide manual review cards for human operators before initiating outreach."},{"id":"comp_3","featureName":"Personalized Outreach Message Generation","category":"OUTREACH_MESSAGING","officialSupport":"HUMAN_IN_THE_LOOP","metaEndpoint":"MESSAGING_POLICY: Bulk Automated DMs are explicitly forbidden under Section 3.b of Platform Terms.","tikTokEndpoint":"DIRECT_MESSAGE_API: Automated mass outreach is restricted. Must use Creator Marketplace or Human dispatch.","policyGuideline":"Instagram & TikTok strictly prohibit bots executing bulk unsolicited DMs. Commercial outreach must be 1-to-1, personalized, and human-approved.","safeImplementation":"AI drafts hyper-specific, context-aware messages referencing verified public posts. Mandatory human review and 1-click verification before dispatch."},{"id":"comp_4","featureName":"Direct Message Dispatch & Conversation Tracking","category":"OUTREACH_MESSAGING","officialSupport":"NATIVE_OFFICIAL_API","metaEndpoint":"POST /v20.0/{ig-user-id}/messages (Instagram Direct API for authorized business messaging window)","tikTokEndpoint":"TikTok Commercial Content / Direct Collaboration API","policyGuideline":"Meta Messenger API permits sending to users who have initiated contact or authorized outreach via Business Direct.","safeImplementation":"Connects official Instagram Messaging Webhooks for incoming replies and provides deep-link dispatch buttons directly into the verified Instagram app."},{"id":"comp_5","featureName":"Multi-Brand Profile & Token Isolation","category":"RELATIONSHIP_CRM","officialSupport":"NATIVE_OFFICIAL_API","metaEndpoint":"Meta Business Manager System User Tokens with scoped 'instagram_basic', 'pages_read_engagement'","tikTokEndpoint":"TikTok Developer App App ID & Secret per brand profile","policyGuideline":"Requires distinct OAuth credentials per legal brand entity to prevent cross-contamination and quota sharing.","safeImplementation":"Stores isolated OAuth tokens per brand profile in Supabase encrypted vault with automatic token refresh."},{"id":"comp_6","featureName":"Follow-Up Scheduling & SLA Reminders","category":"RELATIONSHIP_CRM","officialSupport":"NATIVE_OFFICIAL_API","metaEndpoint":"Internal Event Queue (Inngest / PostgreSQL triggers)","tikTokEndpoint":"Internal Event Queue (Inngest / PostgreSQL triggers)","policyGuideline":"100% internal CRM functionality. No external platform policy restrictions.","safeImplementation":"Enforces 48-hour follow-up windows, team member task assignments, and response rate calculations."}],"timestamp":"2026-09-28T16:30:43.798Z"}