The things that go wrong, and what stops them
This page is a list of things that go wrong at other organisations, and what stops them here.
Your data stays in Australia
The platform runs in AWS Sydney. Nothing about your account or your messages needs to leave the country, which is usually the first thing a privacy team asks about.
An ex-employee cannot still send as your company
Accounts are individual, two-factor authentication is available, and access is removed the moment you remove it. API keys and connected applications are revoked in one click and stop working immediately.
Marketing cannot reach your whole customer base by accident
Eighteen separate permissions decide who can send, who can only look, who can manage contacts and who can touch billing. Sub-accounts keep teams' data apart entirely.
Only your systems can use your keys
Account access can be restricted to the IP addresses you nominate, which sharply limits what a leaked key can be used for.
An AI assistant gets a leash, not a key
Connected assistants are granted a specific scope rather than your credentials, everything they do is logged, and you can revoke them instantly.
What we do not claim
We are not certified against ISO 27001 or SOC 2, and we do not hold an IRAP assessment. If a certification is a requirement of your procurement process, tell us early rather than late.