Security Policy

Last Updated: July 3, 2026

At TurantReply, we take the security of your business data and your customers' conversations seriously. This page outlines the measures we take to protect information processed through our WhatsApp automation and CRM platform.

1. Data Encryption

  • In transit: All data exchanged between your browser, our servers, and the WhatsApp Business API is encrypted using TLS 1.2/1.3 (HTTPS)
  • At rest: Sensitive data, including access tokens and customer information, is encrypted in our databases

2. WhatsApp API Security

  • We use Meta's official WhatsApp Business Platform (Cloud API) via Embedded Signup, ensuring all messaging is routed through Meta-approved, compliant infrastructure
  • Access tokens (System User tokens) are stored securely and never exposed to the client-side application
  • We do not store WhatsApp message content longer than necessary to provide the Service, unless required for your CRM history features

3. Access Controls

  • Role-based access control (RBAC) ensures team members only access data relevant to their role
  • Two-factor authentication (2FA) is available/required for account login
  • All administrative access to production systems is logged and monitored

4. Infrastructure Security

  • Hosted on [AWS/Google Cloud/Azure — specify], leveraging their enterprise-grade physical and network security
  • Regular automated backups with encrypted storage
  • Firewalls, intrusion detection, and DDoS protection are in place at the infrastructure level

5. Application Security

  • Regular security patching and dependency updates
  • Input validation and protection against common vulnerabilities (SQL injection, XSS, CSRF)
  • [If applicable: Periodic penetration testing / vulnerability scanning]

6. Payment Security

  • We do not store full credit/debit card numbers on our servers
  • Payment processing is handled by PCI-DSS compliant third-party payment gateways (e.g., Razorpay, Cashfree)

7. Data Isolation

  • Client data is logically isolated to prevent unauthorized cross-account access
  • Each business's WhatsApp Business Account (WABA) and conversation data is scoped strictly to that account

8. Employee Access

  • Access to production data is limited to authorized personnel on a need-to-know basis
  • Employees undergo confidentiality agreements and security awareness practices

9. Incident Response

In the event of a security incident affecting your data, we will:

  • Investigate and contain the issue promptly
  • Notify affected clients within a reasonable timeframe as required by applicable law
  • Take corrective action to prevent recurrence

10. Your Responsibility

While we secure our platform, you are responsible for:

  • Keeping your account login credentials confidential
  • Ensuring only authorized team members have platform access
  • Promptly reporting any suspected unauthorized access to security@turantreply.com

11. Reporting a Security Vulnerability

If you discover a security vulnerability, please report it responsibly to:

Email: security@turantreply.com

We appreciate responsible disclosure and will respond promptly to verified reports.

12. Contact Us

TurantReply

Email: security@turantreply.com

Address: India