SaarFlow SaarFlow by Techsaar
Security & data protection

Written so you can forward it to IT

SaarFlow handles the conversations a business has with its customers. That is sensitive by definition, so here is exactly how it is held, who can reach it, and what happens if you leave.

You own the account

Your WhatsApp Business Account, your phone number and your conversations belong to you. SaarFlow connects to them as a Meta Tech Provider; it does not take ownership of them. End the relationship and the account stays yours.

Credentials encrypted at rest

Meta access tokens, webhook verify tokens and third-party integration keys are encrypted with AES-256-GCM before they touch the database, and are never sent to a browser — including yours. Screens show a hint such as a0501f26****957, never the value.

One tenant cannot see another

Every record in the database carries the organisation it belongs to, and every query is scoped to the organisation on the request's own token. There is no shared pool and no "all accounts" view for a customer.

Permissions enforced on the server

Which screens a role may open, and whether an agent sees only their own chats, is checked on every API request — not merely hidden from the menu. Hiding a button is not access control, so we do not treat it as any.

Webhooks are signature-verified

Every inbound event from Meta is checked against its X-Hub-Signature-256 HMAC over the exact bytes Meta signed, before anything is parsed. A forged event that merely knows your phone number ID is rejected.

Opt-outs cannot be overridden

A customer who opts out is never messaged again — not by a campaign, not by the API, not by the AI agent. The rule lives in the server, so no screen, integration or mistake can route around it.

In transit and at rest

The boring details, stated plainly

AreaHow it works
TransportHTTPS everywhere, TLS certificates renewed automatically. Plain HTTP is redirected, never served.
PasswordsHashed with bcrypt. Nobody at Techsaar can read a customer's password, and support will never ask for one.
API keysShown once at creation, then stored only as a SHA-256 hash. A lost key is replaced, never recovered.
Secrets in the productAES-256-GCM encryption, keyed from an environment secret that is not in the code repository.
DatabasePostgreSQL on a private Docker network. Not reachable from the public internet.
MediaWhatsApp photos, documents and voice notes are fetched with your own token and stored against your organisation only.
Rate limitingPer-IP limits on the API, with stricter limits on sign-in and registration to blunt brute force.
BackupsDatabase backups are taken before every schema change and kept off the application server.
HostingIndian business data on a dedicated server, administered by Techsaar. No sub-processor resells your conversations.
Your data

Export it, or have it deleted

Nothing about SaarFlow is designed to make leaving difficult. Ask and you get your contacts, conversations and CRM records in a machine-readable form; ask and they are removed.

  • Export of contacts, conversations, leads and reports on request
  • Deletion of an organisation and everything under it, on written request from an admin
  • Meta's own data-deletion callback is implemented, and verified by signed request
  • Your WhatsApp Business Account is disconnected, not absorbed, when you leave

Reporting a vulnerability

If you believe you have found a security problem in SaarFlow, write to support@techsaar.com with enough detail to reproduce it. We will acknowledge within two working days and tell you what we are doing about it.

Please do not test against another customer's account or data. We will not pursue anyone who reports a genuine issue in good faith.

Due diligence welcome

Send us your security questionnaire

We would rather answer it properly before you buy than be asked about it after an incident. Send the document and we will fill it in.

Techsaar · Indore, Madhya Pradesh · Mon–Sat, 10am–7pm IST