Security
Effective 29 September 2026 · Syslice Technologies Private Limited
Dhaka Ka Bas, Nawalgarh, Jhunjhunu, Rajasthan 333305, India
What we actually do, in terms specific enough to hold us to. We would rather describe a real control than claim a certification we do not hold.
Isolation
Every customer’s conversation data lives in its own database, not in shared tables separated by a tenant column. That boundary is structural: a query that forgets a filter cannot return another customer’s data, because the data is not in the database being queried. Each connection carries a guard so a mis-resolved connection fails loudly rather than writing to the wrong place.
Credentials and encryption
- All traffic is encrypted in transit — between you and us, and between us and Meta.
- WhatsApp access tokens are encrypted at rest with AES-256-GCM under a key held outside the database, and are never written to logs or error messages.
- Passwords are stored with a memory-hard hash, never reversibly.
- The service refuses to start if its encryption key is missing or malformed, rather than starting and failing later at the first message.
Access
- The internal operations console binds to loopback and is not reachable from the public internet; access additionally requires a second factor.
- Administrative actions are written to an append-only audit log recording who did what, when, and what changed.
- Staff access to customer data is limited to what support requires and is logged.
Platform integrity
- Webhook deliveries are signature-verified against Meta’s app secret before anything is processed.
- Outbound fetches are restricted, so a link in a message cannot be used to reach internal addresses or cloud metadata endpoints.
- Uploads are size-limited and scanned, and media is served from signed, expiring URLs.
- The codebase is continuously scanned for vulnerable dependencies, leaked secrets and common weaknesses, and the pipeline fails on high-severity findings.
Backups and continuity
Databases are backed up on a schedule and restores are tested — a backup that has never been restored is a hope, not a control. Backups are encrypted and expire on a rolling schedule.
Reporting a vulnerability
Email [email protected] with Security in the subject. Tell us what you found and how to reproduce it. We acknowledge within 72 hours.
We will not pursue legal action against anyone who reports in good faith, gives us reasonable time to fix the issue before disclosing, and does not access, modify or delete other people’s data while testing. Please do not run automated scans against production, and do not test denial of service.