Skip to content
customerio-security-basics logo

Customer.io Security Basics

customerio-security-basics

Apply Customer.io security best practices. Use when implementing secure integrations, handling PII, or setting up proper access controls. Trigger with phrases like "customer.io security", "customer.io pii", "secure customer.io", "customer.io gdpr".

SKILL.md

Full skill instructions

Customer.io Security Basics

Overview

Implement security best practices for Customer.io integrations including credential management, PII handling, and access controls.

Prerequisites

  • Customer.io account with admin access
  • Understanding of your data classification
  • Environment variable management

Instructions

Step 1: Secure Credential Management

// lib/​secrets.ts
import { SecretManagerServiceClient } from '@google-cloud/​secret-manager';

// Use a secrets manager instead of env vars for production
async function getCustomerIOCredentials(): Promise<{
  siteId: string;
  apiKey: string;
}> {
  // Option 1: Google Cloud Secret Manager
  const client = new SecretManagerServiceClient();
  const [siteIdVersion] = await client.accessSecretVersion({
    name: 'projects/​PROJECT_ID/​secrets/​customerio-site-id/​versions/​latest'
  });
  const [apiKeyVersion] = await client.accessSecretVersion({
    name: 'projects/​PROJECT_ID/​secrets/​customerio-api-key/​versions/​latest'
  });

  return {
    siteId: siteIdVersion.payload?.data?.toString() || '',
    apiKey: apiKeyVersion.payload?.data?.toString() || ''
  };
}

// Option 2: AWS Secrets Manager
import { SecretsManager } from '@aws-sdk/​client-secrets-manager';

async function getCredentialsFromAWS() {
  const client = new SecretsManager({ region: 'us-east-1' });
  const response = await client.getSecretValue({
    SecretId: 'customerio-credentials'
  });
  return JSON.parse(response.SecretString || '{}');
}

Step 2: PII Data Handling

// lib/​pii-handler.ts
import crypto from 'crypto';

// Hash sensitive identifiers before sending
function hashPII(value: string): string {
  return crypto
    .createHash('sha256')
    .update(value + process.env.PII_SALT)
    .digest('hex');
}

// Sanitize attributes before sending to Customer.io
function sanitizeUserAttributes(attributes: Record<string, any>): Record<string, any> {
  const sensitiveFields = ['ssn', 'credit_card', 'password', 'bank_account'];
  const piiFields = ['phone', 'address', 'date_of_birth'];

  const sanitized = { ...attributes };

  // Remove highly sensitive fields
  for (const field of sensitiveFields) {
    delete sanitized[field];
  }

  // Hash PII fields if needed for matching but not display
  for (const field of piiFields) {
    if (sanitized[field]) {
      sanitized[`${field}_hash`] = hashPII(sanitized[field]);
      // Optionally remove plain text version
      // delete sanitized[field];
    }
  }

  return sanitized;
}

// Usage
const safeAttributes = sanitizeUserAttributes({
  email: '[email protected]',
  phone: '+1234567890',
  ssn: '123-45-6789', // Will be removed
  plan: 'premium'
});

Step 3: API Key Rotation

// scripts/​rotate-api-key.ts
async function rotateAPIKey(): Promise<void> {
  console.log('API Key Rotation Checklist:');
  console.log('1. Generate new API key in Customer.io dashboard');
  console.log('2. Update secrets manager with new key');
  console.log('3. Deploy application with new key');
  console.log('4. Verify integration works with new key');
  console.log('5. Revoke old API key in dashboard');
  console.log('6. Update documentation');

  // Automated rotation (if using secrets manager)
  // 1. Create new key via API (if supported)
  // 2. Update secret in manager
  // 3. Wait for propagation
  // 4. Revoke old key
}

// Schedule rotation every 90 days
// Add to cron or scheduled task

Step 4: Webhook Security

// lib/​webhook-security.ts
import crypto from 'crypto';
import { Request, Response, NextFunction } from 'express';

// Verify Customer.io webhook signatures
function verifyWebhookSignature(
  payload: string,
  signature: string,
  secret: string
): boolean {
  const expectedSignature = crypto
    .createHmac('sha256', secret)
    .update(payload)
    .digest('hex');

  return crypto.timingSafeEqual(
    Buffer.from(signature),
    Buffer.from(expectedSignature)
  );
}

// Express middleware for webhook verification
export function webhookAuthMiddleware(webhookSecret: string) {
  return (req: Request, res: Response, next: NextFunction) => {
    const signature = req.headers['x-cio-signature'] as string;

    if (!signature) {
      return res.status(401).json({ error: 'Missing signature' });
    }

    const payload = JSON.stringify(req.body);

    if (!verifyWebhookSignature(payload, signature, webhookSecret)) {
      return res.status(401).json({ error: 'Invalid signature' });
    }

    next();
  };
}

// Usage
app.post('/​webhooks/​customerio',
  webhookAuthMiddleware(process.env.CUSTOMERIO_WEBHOOK_SECRET!),
  (req, res) => {
    // Handle verified webhook
  }
);

Step 5: Access Control

// lib/​access-control.ts
interface TeamMember {
  email: string;
  role: 'admin' | 'editor' | 'viewer';
  permissions: string[];
}

// Recommended role-based access
const rolePermissions = {
  admin: [
    'manage_api_keys',
    'manage_team',
    'manage_integrations',
    'view_all_data',
    'send_campaigns'
  ],
  editor: [
    'create_campaigns',
    'edit_campaigns',
    'view_analytics',
    'manage_segments'
  ],
  viewer: [
    'view_campaigns',
    'view_analytics'
  ]
};

// Audit logging for security-sensitive operations
function logSecurityEvent(event: {
  action: string;
  actor: string;
  resource: string;
  details?: Record<string, any>;
}) {
  console.log(JSON.stringify({
    type: 'security_audit',
    timestamp: new Date().toISOString(),
    ...event
  }));
}

Step 6: Data Retention

// lib/​data-retention.ts
import { APIClient } from '@customerio/​track';

// Suppress/​delete users for GDPR/​CCPA compliance
async function deleteUserData(client: APIClient, userId: string) {
  // 1. Suppress the user (stops all messaging)
  await client.suppress(userId);

  // 2. Request full deletion through Customer.io dashboard or API
  // Note: Full deletion may require support ticket

  console.log(`User ${userId} suppressed and deletion requested`);
}

// Anonymous historical data retention
function anonymizeForAnalytics(userData: Record<string, any>) {
  return {
    ...userData,
    email: undefined,
    phone: undefined,
    first_name: undefined,
    last_name: undefined,
    // Keep aggregated/​analytical data
    plan: userData.plan,
    signup_date: userData.created_at,
    total_events: userData.event_count
  };
}

Security Checklist

  • API keys stored in secrets manager (not env vars in code)
  • API keys rotated every 90 days
  • Webhook signatures verified
  • PII sanitized before sending
  • Minimum necessary data sent to Customer.io
  • Team access follows least-privilege principle
  • Audit logging enabled for sensitive operations
  • GDPR/​CCPA deletion process documented
  • SSL/​TLS enforced for all API calls

Error Handling

IssueSolution
Exposed credentialsRotate immediately, audit access
PII leakDelete from Customer.io, notify DPO
Unauthorized accessReview access logs, revoke access

Resources

Next Steps

After implementing security, proceed to customerio-prod-checklist for production readiness.

More skills from Dicklesworthstone

environment-setup-guide logo
Dicklesworthstone/pi_agent_rust

environment-setup-guide

Guide developers through setting up development environments with proper tools, dependencies, and configurations

1.8K 0
View
exa-policy-guardrails logo
Dicklesworthstone/pi_agent_rust

exa-policy-guardrails

Implement Exa lint rules, policy enforcement, and automated guardrails. Use when setting up code quality rules for Exa integrations, implementing pre-commit hooks, or configuring CI policy checks for Exa best practices. Trigger with phrases like "exa policy", "exa lint", "exa guardrails", "exa be...

1.8K 0
View
documenso-ci-integration logo
Dicklesworthstone/pi_agent_rust

documenso-ci-integration

Configure CI/CD pipelines for Documenso integrations. Use when setting up automated testing, deployment pipelines, or continuous integration for Documenso projects. Trigger with phrases like "documenso CI", "documenso GitHub Actions", "documenso pipeline", "documenso automated testing".

1.8K 0
View
openrouter-model-availability logo
Dicklesworthstone/pi_agent_rust

openrouter-model-availability

Build check model availability and implement fallback chains. Use when building resilient systems or handling model outages. Trigger with phrases like 'openrouter availability', 'openrouter fallback', 'openrouter model down', 'openrouter health check'.

1.8K 0
View
langfuse-enterprise-rbac logo
Dicklesworthstone/pi_agent_rust

langfuse-enterprise-rbac

Configure Langfuse enterprise organization management and access control. Use when implementing team access controls, configuring organization settings, or setting up role-based permissions for Langfuse projects. Trigger with phrases like "langfuse RBAC", "langfuse teams", "langfuse organization"...

1.8K 0
View
cursor-compliance-audit logo
Dicklesworthstone/pi_agent_rust

cursor-compliance-audit

Execute compliance and security auditing for Cursor usage. Triggers on "cursor compliance", "cursor audit", "cursor security review", "cursor soc2", "cursor gdpr". Use when analyzing or auditing cursor compliance audit. Trigger with phrases like "cursor compliance audit", "cursor audit", "cursor".

1.8K 0
View
apollo-ci-integration logo
Dicklesworthstone/pi_agent_rust

apollo-ci-integration

Configure Apollo.io CI/CD integration. Use when setting up automated testing, continuous integration, or deployment pipelines for Apollo integrations. Trigger with phrases like "apollo ci", "apollo github actions", "apollo pipeline", "apollo ci/cd", "apollo automated tests".

1.8K 0
View
python-script logo
Dicklesworthstone/pi_agent_rust

python-script

Create robust Python automation with full logging and safety checks. Use when tasks need complex data processing, authenticated API work, conditional file operations, or error handling beyond simple shell commands.

1.8K 0
View
posthog-multi-env-setup logo
Dicklesworthstone/pi_agent_rust

posthog-multi-env-setup

Configure PostHog across development, staging, and production environments. Use when setting up multi-environment deployments, configuring per-environment secrets, or implementing environment-specific PostHog configurations. Trigger with phrases like "posthog environments", "posthog staging", "po...

1.8K 0
View
ai-agents-architect logo
Dicklesworthstone/pi_agent_rust

ai-agents-architect

Expert in designing and building autonomous AI agents. Masters tool use, memory systems, planning strategies, and multi-agent orchestration. Use when: build agent, AI agent, autonomous agent, tool use, function calling.

1.8K 0
View
insecure-deserialization-checker logo
Dicklesworthstone/pi_agent_rust

insecure-deserialization-checker

Validate insecure deserialization checker operations. Auto-activating skill for Security Fundamentals. Triggers on: insecure deserialization checker, insecure deserialization checker Part of the Security Fundamentals skill category. Use when working with insecure deserialization checker functiona...

1.8K 0
View
path-traversal-finder logo
Dicklesworthstone/pi_agent_rust

path-traversal-finder

Manage path traversal finder operations. Auto-activating skill for Security Fundamentals. Triggers on: path traversal finder, path traversal finder Part of the Security Fundamentals skill category. Use when working with path traversal finder functionality. Trigger with phrases like "path traversa...

1.8K 0
View

Popular AI tools

Kaiber logo
Video

Kaiber

Generate, edit, and beat-sync AI video with leading models in one workspace.

Paid
View
Vimcal logo
Productivity

Vimcal

The world's fastest calendar for remote work

Free
View

Transform Your Design with AI Designer by ImgCreator.ai

Freemium
View
Akool AI logo
Content & writing

Akool AI

Revolutionizing Video Production with AI-Powered Creativity

Paid
View

Extend an image past the frame and let AI fill the new aspect ratio.

Freemium
View
StarByFace logo
Security

StarByFace

Discover your celebrity doppelgänger with StarByFace!

Free
View
C

ChainClarity explains 700+ crypto whitepapers in plain English, with layered summaries, comparisons, research tools, alerts, and a $4.99 Pro plan.

Freemium
View
Opus Clip logo
Coding & apps

Opus Clip

Opus.ai: Revolutionize Your Web Experience

Free
View