In plain words: We use HTTPS, workspace isolation, access controls, and safe sending limits. You still control who is in your team and how your WhatsApp number is used.
1. Our commitment
Messageroots handles business messaging data. We design the platform so each Customer’s workspace is separated, credentials are protected, and only authorised staff can access systems needed to run the product.
2. Application security
- Encrypted transport (HTTPS/TLS) for the website and app
- Session protection and CSRF safeguards on web forms
- Role-based access inside workspaces (where enabled)
- OTP / WhatsApp login options to reduce password-only risk
- Input validation on uploads (including images shared in campaigns, inbox, CRM, and store)
3. Data handling & access
- Customer data is stored in controlled databases with backups appropriate to the environment
- Staff access to production is limited and audited where tooling allows
- Media files (product images, campaign images) are stored on secured storage paths intended for authorised delivery to WhatsApp
- We do not sell Customer contact lists or chat content
See also our Privacy Policy.
4. WhatsApp connection security
- Cloud API — uses Meta-issued tokens; store them carefully and rotate if exposed.
- Linked phone (QR) — behaves like WhatsApp Web. Keep the device online, protect the phone with a lock screen, and disconnect sessions you do not recognise.
- Gateway and queue workers should run only on trusted servers with restricted network access.
- Safe-sending controls (delays, daily caps, opt-in) reduce spam risk to your number — use them.
5. Operations & continuity
- Monitoring and logging for availability and abuse signals
- Dependency and platform updates on a regular cadence
- Incident response: investigate, contain, notify affected Customers when legally required
6. Your responsibilities
- Use strong device security and do not share OTP codes
- Invite only trusted teammates; remove access when people leave
- Message only consented contacts; respect STOP and local telecom rules
- Do not upload unlawful or infringing media
- Review Meta’s policies when using WhatsApp Business features
7. Report a security issue
If you believe you found a vulnerability in Messageroots, email security@messageroots.com with steps to reproduce. Please avoid public disclosure until we can investigate.
Related: Privacy Policy · Terms of Service · Cookie Policy