Controls that stop abuse early.
Hopwire limits how fast codes go to one number or number range, sends only to Indian numbers, and can stop a sender or template at once. Your team signs in with MFA every time.
What you get
OTP velocity limits
Limits per recipient and per number range stop pumping attacks, returning 429 with Retry-After.
India only
Sends to numbers outside India are refused during the beta.
Emergency stop
Sending can be stopped for an account, tenant, sender or template, checked right before each dispatch.
Mandatory MFA
Everyone signs in with an authenticator app or an email code. Sensitive actions ask for a fresh check.
Roles and scoped keys
Owner, developer and viewer roles. API keys carry only the permissions and tenants they need, and are shown once.
Anomaly detection and link screening
At launchAlerts on unusual volume or destinations, and outbound links checked before dispatch.
Passkeys and custom permissions
At launchPasskey sign-in, finer permissions and service accounts.
SSO and SCIM
Release 2Single sign-on and automatic user provisioning.
Questions
Who can trigger an emergency stop?
Hopwire staff, through an audited process. Blocked sends return sending_stopped.
Can I turn off MFA?
No. MFA is mandatory for every person who signs in.
What stops a leaked API key from sending anywhere?
Keys are limited to one environment, their permissions and their tenants, destinations are limited to India, and OTP velocity limits still apply.
Related
- SecurityAvailableData hosted in Mumbai with Hyderabad backups, encryption for secrets and codes, mandatory MFA, scoped keys and audit trails.
- SSO and SCIMRelease 2SAML and OIDC single sign-on with SCIM provisioning, and MFA that still applies. Planned for Release 2.
- OTPAvailableDeliver your one-time codes on WhatsApp with SMS fallback. You generate and check the code; Hopwire delivers it and never stores it.
Start with the beta.
Hopwire is free during the invite-only beta. Tell us what you send and we will reply by email.