Security
How AyuChat protects your business data, your customers' conversations, and your WhatsApp Business Account.
1. Our Approach to Security
AyuChat sits between your business and your customers' most personal channel - WhatsApp. We treat the security of that relationship as a first-class responsibility, not an afterthought. This page describes the technical and organizational measures we maintain to protect your data.
2. Infrastructure & Hosting
- AyuChat is hosted on reputable cloud infrastructure providers with industry-standard physical and network security certifications.
- Our infrastructure is deployed across isolated environments for production, staging, and development, preventing cross-contamination of data.
- We maintain automated backups of critical data, tested periodically for successful restoration.
3. Encryption
- All data in transit between your browser, our API, and our servers is encrypted using TLS 1.2 or higher.
- Sensitive data at rest, including message content and contact information, is encrypted using industry-standard encryption algorithms.
- API keys and credentials are stored using secure hashing and secrets-management practices, never in plain text.
4. Access Control & Authentication
- Role-based access control (RBAC) lets you define exactly what each team member in your organization can view, launch, edit, or export.
- API keys can be scoped to specific permissions (read-only, send-only, or full access) and revoked instantly from your dashboard.
- All administrative access to production systems by AyuChat staff is logged and subject to internal review.
5. WhatsApp API & Meta Compliance
AyuChat operates exclusively on Meta's official WhatsApp Business Platform (Cloud API). We do not use unofficial, cloned, or grey-market WhatsApp access methods of any kind. This means:
- Your WhatsApp Business Account remains verified and compliant with Meta's platform policies at all times.
- Message delivery infrastructure is subject to Meta's own security and reliability standards, in addition to ours.
- We do not store your Meta/Facebook login credentials; authentication is handled via Meta's official OAuth flow.
6. Payment Security
All payment processing is handled by Razorpay, a PCI-DSS compliant payment gateway. AyuChat does not store your full card numbers, CVV, or net banking credentials on its own servers at any point.
7. Monitoring & Incident Response
- We maintain continuous monitoring of our infrastructure for unusual activity, with automated alerting for anomalies.
- In the event of a security incident affecting your data, we will notify affected customers without undue delay, in accordance with applicable Indian law.
- Our current system status is published at status.ayuchat.in.
8. Employee Access & Training
Access to production systems and customer data is limited to employees who require it for their role, governed by the principle of least privilege. All employees undergo periodic security and data-handling training.
9. Responsible Disclosure
If you believe you have found a security vulnerability in AyuChat, we want to hear from you. Please report it to security@ayuchat.in with sufficient detail to reproduce the issue. We ask that you do not publicly disclose the issue until we have had a reasonable opportunity to address it, and we commit to acknowledging reports within 48 hours.
10. Contact Our Security Team
For any security-related questions or concerns, reach out to security@ayuchat.in.
Grievance Officer
In accordance with the Information Technology Act, 2000 and the rules made thereunder, the details of the Grievance Officer are provided below for any complaints or concerns regarding this policy.
Grievance Officer, Agnistoka Digital Universe Tech Private Limited
grievance@ayuchat.in
Agnistoka Technology, 7 No. chauraha, Haksar colony, Morar, Gwalior, M.P. 474006, India
