Your data is separated from every other business
- Every database query runs inside one organisation's scope: the data layer refuses a read or write that is not bound to an organisation.
- An automated isolation suite signs in as one organisation and tries every API endpoint against another's records; it must find zero leaks before a release.
Encryption
- Our public addresses are served over HTTPS (TLS) only.
- The connection between our servers and the database requires TLS.
- Credentials you connect — such as WhatsApp, payment-gateway and AI-provider keys — are stored encrypted with AES-256-GCM under a per-secret data key.
- Passwords are never stored; we keep only a scrypt hash.
Backups
- The database is backed up with a scripted dump, and a full restore has been rehearsed and timed, with every table compared against the source.
Access control and accountability
- Every action in a workspace is checked against the member's role and permissions.
- Changes in a workspace are written to an audit log you can review.
- Sign-in is by password or a one-time code by email or SMS, with rate limits on attempts per account and per address.
- Session cookies are HTTP-only, so page scripts cannot read them.
- The API trusts a visitor's address only from our own proxies, and caps the size of every request.
Verified inbound events
- Payment events from Razorpay are accepted only with a valid signature.
- WhatsApp events are accepted only with the shared secret configured for them.
- Video-meeting events from LiveKit are verified before they are processed.
Payments
- Payments are processed by Razorpay, which is PCI-DSS certified. Card and bank details are entered with Razorpay; Selfeey does not store card numbers.
AI providers
- AI features run on OpenAI, Groq, Anthropic and Google Gemini through Selfeey's AI gateway, which records every request and its cost against your workspace.
Calls and recordings
- AI calls follow per-country rules for calling hours and do-not-call checks; an unknown country or time zone means the call is not placed.
- A call is recorded only with an announcement; in places that require every party's consent, the script must ask.
- Meeting recording starts only after the host confirms the participants' consent.
India's DPDP Act 2023
Our Privacy Policy sets out the rights the Act gives you and how to use them, and our Data Processing Addendum covers the personal data you process through Selfeey.
- Our database runs in India, in AWS's Mumbai region (ap-south-1).
Reporting a security issue
If you believe you have found a security issue, write to support@selfeey.com with "Security" in the subject and the details to reproduce it. Please do not access other people's data or disrupt the service while testing. We will acknowledge your report and keep you informed.