Security at MsgHub

Your customer data is yours. We just keep it locked.

Your WhatsApp chats, your contacts, your IndiaMART leads. Encrypted in transit and at rest, isolated per business, and never sold or used to train models that anyone else benefits from.

Built in India · Encrypted at rest and in transit · Independent researchers test us.

Four promises

The things we will never do, and the things we always will.

We don’t mine your conversations.

Our AI processes your chats to reply on your behalf — that’s it. We don’t sell your data, share it with other businesses, or use it to train models anyone else benefits from. Staff access is limited to what support and debugging require, and actions are written to an audit log.

Your data is yours alone.

Every business is isolated at the database level, so one tenant can never read another’s contacts or conversations. Data is encrypted in transit and at rest, and the backups are encrypted too.

If you leave us, we delete everything.

Cancel your account and we erase your contacts, messages, leads and AI training data from live systems within 30 days. Encrypted backups age out on their normal retention cycle after that. Ask and we’ll confirm in writing when it’s done.

If anything goes wrong, you hear in 24 hours.

No legal team running interference. No two-week PR cycle. If a security incident touches your data, you get a direct email within 24 hours of us confirming it — what happened, what we did, and what (if anything) you need to do.

How we lock it

The locks on the vault, in plain English.

No jargon. Six things we do to keep your data where it belongs.

🔒

Bank-grade encryption

The same kind of encryption your bank uses for net-banking. Even if our database files were stolen, the contents would be unreadable noise.

🏢

Separate rooms per business

Your data and another business’s data are in different vaults — not different drawers. Even if a query goes wrong, it can’t reach across.

👁️

Even our staff can’t peek

Engineers don’t have a “view customer inbox” button. Support can’t open your messages. Access requires your written approval, every time.

🛂

Two-factor login

Add a second password code from your phone — so even if someone gets your email password, they still can’t walk into your MsgHub account.

🔔

Every action is logged

Who logged in, what they changed, when they sent it. If you ever need to audit, the trail is there — you can’t edit it, and we can’t hide it.

🛡️

Outside researchers test us

We run an open Vulnerability Disclosure Program. Independent security researchers actively look for holes — and we fix them publicly. See the Hall of Fame →

If something goes wrong

No silence. No spin. Just a phone call.

A lot of companies wait weeks to tell customers about a breach. We don’t. Here’s exactly what happens if anything ever does.

  1. 1

    We detect or confirm the issue

    Could be our monitoring, could be a researcher, could be you reporting it. Either way, the clock starts immediately.

  2. 2

    We stop the bleeding

    Affected access is locked down. Vulnerable code is rolled back or patched. This usually happens within the first hour.

  3. 3

    You hear from us within 24 hours

    A direct email from the founder — not a press release. What we know, what we did, what you should do, and a single point of contact for follow-up questions.

  4. 4

    We write it up publicly

    Within 30 days, a post-incident note on our status page. What happened, what we changed, so you (and every other customer) know we’ve actually fixed it. View status page →

Independent validation

We don’t mark our own homework.

Anyone can write “we’re secure” on a website. We invite independent security researchers to actively try to break MsgHub — and credit every valid finding publicly. Three researchers have already earned Founding Researcher status.

Common questions

The questions everyone asks.

Can MsgHub employees read my WhatsApp messages?

No. Routine support and engineering work doesn’t touch message content. The AI processes your chats automatically, but no human at MsgHub has a button to open your inbox. The rare times we genuinely need access to debug something, we ask in writing and you decide.

Where is my data physically stored?

On dedicated servers we control, encrypted at rest, with encrypted off-site backups. Every sub-processor we use and where each one operates is listed in our Privacy Policy. Your data is never sold, and never used to train shared AI models.

What happens to my data if I cancel?

You can export everything — contacts, messages, leads — before you go. Then we delete your account and your data from live systems within 30 days; encrypted backups age out on their normal retention cycle after that. Ask and we’ll confirm in writing when it’s done.

Does the AI “learn” from my customer conversations?

The AI uses your own products, FAQs, and past replies to answer customers in your account. Your data is never used to train a shared model that other businesses can benefit from. Your knowledge stays your knowledge.

I found a security issue. Who do I tell?

Email [email protected]. We acknowledge within 3 business days and credit valid reports publicly. Full policy at /bug-bounty.

Have a security question we didn’t answer?

Mail the founder directly. No ticket system, no chatbot.