Skip to content

Access your apps

Sign in to the products you already use.

Trust & security

What we protect, how we protect it, and who we are on paper.

Everything a security, legal or procurement review usually asks for, in one place — with every claim traceable to a published policy.

Company verification

Who you would be contracting with

The registered particulars, exactly as they appear in our legal documents.

Legal name
Nebkern Technology
Constitution
Sole proprietorship
Registered address
Siliguri, West Bengal, India
Udyam (MSME) registration
UDYAM-WB-06-0069607
Meta status
Official Meta Tech Provider

Data protection

How our products protect customer data

Summarised from Instant's published Security Policy, which describes the controls actually operated — not the ones that sound reassuring.

Hosted in India

Workspace data is hosted in Mumbai, India (ap-south-1). Secrets live in the deployment environment, never in the code repository.

Encrypted in transit and at rest

Traffic is served over HTTPS with TLS, and data sits on encrypted volumes. Channel and AI provider credentials get a second layer: AES-256-GCM under a key held only on the server.

Isolated at the database layer

PostgreSQL row-level security scopes every row to the workspace that owns it, so a query cannot return another workspace’s data even if application logic is wrong.

Verified integrations

Inbound Meta webhooks are checked against an HMAC-SHA256 signature before any data is read. Channels connect through official OAuth, and outbound webhooks are signed per endpoint.

Least-privilege access

Roles decide who can read conversations or change settings. Back-office access is limited to an explicit allow-list, and staff reach customer data only to run the service or resolve a request.

Incident response

Suspected incidents are contained first, then investigated. Where a personal data breach affects your data, you are notified without undue delay and within 72 hours.

What we do not claim

The limits, stated plainly

A security page is more useful when it is honest about its edges.

  • We do not currently claim SOC 2, ISO 27001 or PCI DSS certification. Card and UPI payments are handled entirely by Razorpay, which holds its own compliance — card details are never received or stored on our servers.
  • Messages on the WhatsApp Business Platform are not end-to-end encrypted the way personal WhatsApp chats are. A business API message is readable by the business and its platform — that is what makes a shared team inbox possible.
  • Meta processes message data on its own global infrastructure, under its own terms. That is outside our control, and unavoidable on any WhatsApp Business Platform product.
  • No system is perfectly secure, and no provider can honestly promise otherwise.

Report a vulnerability

Found a security issue? We want to hear about it.

Email contact@instant.nebkern.com with enough detail to reproduce it — the affected URL or endpoint, the steps, and what you were able to access. We will acknowledge it, investigate, keep you updated, and credit you if you would like that.

Ground rules for research

  1. 1Give us a reasonable opportunity to fix an issue before disclosing it publicly.
  2. 2Test only against your own account and data. If a flaw would let you reach another customer's data, stop and tell us instead of proving it.
  3. 3No denial-of-service testing, social engineering, physical attacks, or automated scanning that degrades the service for others.
  4. 4We will not pursue legal action over good-faith research that follows these rules.

Running a security or procurement review?

If your process needs a security questionnaire completed or current documentation shared, write to us and we will work through it with you.