Trust & security
What we protect, how we protect it, and who we are on paper.
Everything a security, legal or procurement review usually asks for, in one place — with every claim traceable to a published policy.
Company verification
Who you would be contracting with
The registered particulars, exactly as they appear in our legal documents.
- Legal name
- Nebkern Technology
- Constitution
- Sole proprietorship
- Registered address
- Siliguri, West Bengal, India
- Udyam (MSME) registration
- UDYAM-WB-06-0069607
- Meta status
- Official Meta Tech Provider
- Contact
- contact@instant.nebkern.com
Data protection
How our products protect customer data
Summarised from Instant's published Security Policy, which describes the controls actually operated — not the ones that sound reassuring.
Hosted in India
Encrypted in transit and at rest
Isolated at the database layer
Verified integrations
Least-privilege access
Incident response
What we do not claim
The limits, stated plainly
A security page is more useful when it is honest about its edges.
- We do not currently claim SOC 2, ISO 27001 or PCI DSS certification. Card and UPI payments are handled entirely by Razorpay, which holds its own compliance — card details are never received or stored on our servers.
- Messages on the WhatsApp Business Platform are not end-to-end encrypted the way personal WhatsApp chats are. A business API message is readable by the business and its platform — that is what makes a shared team inbox possible.
- Meta processes message data on its own global infrastructure, under its own terms. That is outside our control, and unavoidable on any WhatsApp Business Platform product.
- No system is perfectly secure, and no provider can honestly promise otherwise.
Policies
Every published policy
Issued by Nebkern Technology and published alongside Instant, the product they govern.
Privacy Policy
What we collect, why we have it, who else sees it, and how to get it back or get it deleted.
Terms & Conditions
What you can expect from us, what we need from you, and what happens when something goes wrong.
Security Policy
The controls we actually operate, plus an honest account of what we do not claim.
Data Processing Agreement
How we handle the personal data we hold on your instructions. It applies from the moment you accept the Terms.
Subprocessor List
Every third party that touches your data, what each can see, and how to object.
Cancellation & Refunds
Cancel in two clicks, keep what you paid for until the period ends, and exactly when money comes back.
Report a vulnerability
Found a security issue? We want to hear about it.
Email contact@instant.nebkern.com with enough detail to reproduce it — the affected URL or endpoint, the steps, and what you were able to access. We will acknowledge it, investigate, keep you updated, and credit you if you would like that.
Ground rules for research
- 1Give us a reasonable opportunity to fix an issue before disclosing it publicly.
- 2Test only against your own account and data. If a flaw would let you reach another customer's data, stop and tell us instead of proving it.
- 3No denial-of-service testing, social engineering, physical attacks, or automated scanning that degrades the service for others.
- 4We will not pursue legal action over good-faith research that follows these rules.
Running a security or procurement review?
If your process needs a security questionnaire completed or current documentation shared, write to us and we will work through it with you.