Privacy Policy & Data Isolation Protocol

Last Updated: May 2026

At MsgPlus, we design our platforms with security-first engineering principles. Your enterprise data privacy, isolated session infrastructure, and operational reliability are our highest priorities.

1. Complete Tenant Isolation Policy

We enforce strict cryptographic and namespace isolation across all sessions, files, databases, and memory buffers. Your customer database, contact logs, and media assets are completely segmented from other users, fully eliminating any chance of data leak or session crossover.

2. Credential & Access Token Security

All generated Personal Access Tokens are cryptographically hashed using industry-standard hashing algorithms (Laravel Sanctum). We do not store plain-text access tokens in our databases. The visual values of newly created API tokens are shown to users once and can never be retrieved by administrators or database personnel.

3. WhatsApp Session Runtime Protection

Each active WhatsApp session runs in its own isolated browser runtime (via headless Chromium). System sessions are routed using distinct IP proxies to mimic natural user behaviors, strictly complying with digital communication security best practices.

4. AI Telemetry & Observability Auditing

Telemetry data collected via the Observability Layer (such as ACK latencies and AI cost distributions) is aggregated safely under strict tenant scopes. We use circular cache memory buffers to automatically overwrite and flush oldest tracer entries, preventing bulk data accumulation.