Security you can check.
Your data, your team's sign-ins and your backups stay in India. Secrets and codes are encrypted, access is scoped, and actions are recorded.
What you get
Data in India
Primary data, logs and sign-in data in Oracle Cloud Mumbai. Disaster-recovery copies in Hyderabad.
Encryption
Encrypted in transit. Provider credentials, WhatsApp PINs, webhook secrets and OTP codes use envelope encryption and are never shown again.
Keys stored as hashes
API keys are shown once and stored only as keyed hashes.
Mandatory MFA
Every person signs in with an authenticator app or email code, and sensitive actions need a fresh check.
Isolation enforced twice
Tenant and environment boundaries are checked in every query and again by database row-level security.
Audit trails
Administrative actions and message histories are recorded, with sensitive values redacted before storage.
Staff access visible to you
At launchA staff console with time-bound, reason-coded access that you can see in a log.
Questions
Does any data leave India?
Our stores, backups and logs stay in India. Messages necessarily pass through provider platforms such as Meta to be delivered.
How long do you keep message content?
Rendered message bodies for 30 days, then only delivery records, which are kept for a year. OTP codes are never stored.
Can Hopwire staff read my messages?
Staff actions are audited. Time-bound, reasoned access that you can review is planned with the staff console in Release 1.
Related
- Trust and complianceAvailableHow Hopwire handles DLT, consent and data protection: processor for your messages, data kept in India, sub-processors to be published.
- Security controlsAvailableOTP fraud limits, India-only destinations, emergency stop, mandatory MFA and roles for your team.
- SSO and SCIMRelease 2SAML and OIDC single sign-on with SCIM provisioning, and MFA that still applies. Planned for Release 2.
Start with the beta.
Hopwire is free during the invite-only beta. Tell us what you send and we will reply by email.