You own the account
Your WhatsApp Business Account, your phone number and your conversations belong to you. SaarFlow connects to them as a Meta Tech Provider; it does not take ownership of them. End the relationship and the account stays yours.
SaarFlow handles the conversations a business has with its customers. That is sensitive by definition, so here is exactly how it is held, who can reach it, and what happens if you leave.
Your WhatsApp Business Account, your phone number and your conversations belong to you. SaarFlow connects to them as a Meta Tech Provider; it does not take ownership of them. End the relationship and the account stays yours.
Meta access tokens, webhook verify tokens and third-party integration keys are encrypted with AES-256-GCM before they touch the database, and are never sent to a browser — including yours. Screens show a hint such as a0501f26****957, never the value.
Every record in the database carries the organisation it belongs to, and every query is scoped to the organisation on the request's own token. There is no shared pool and no "all accounts" view for a customer.
Which screens a role may open, and whether an agent sees only their own chats, is checked on every API request — not merely hidden from the menu. Hiding a button is not access control, so we do not treat it as any.
Every inbound event from Meta is checked against its X-Hub-Signature-256 HMAC over the exact bytes Meta signed, before anything is parsed. A forged event that merely knows your phone number ID is rejected.
A customer who opts out is never messaged again — not by a campaign, not by the API, not by the AI agent. The rule lives in the server, so no screen, integration or mistake can route around it.
| Area | How it works |
|---|---|
| Transport | HTTPS everywhere, TLS certificates renewed automatically. Plain HTTP is redirected, never served. |
| Passwords | Hashed with bcrypt. Nobody at Techsaar can read a customer's password, and support will never ask for one. |
| API keys | Shown once at creation, then stored only as a SHA-256 hash. A lost key is replaced, never recovered. |
| Secrets in the product | AES-256-GCM encryption, keyed from an environment secret that is not in the code repository. |
| Database | PostgreSQL on a private Docker network. Not reachable from the public internet. |
| Media | WhatsApp photos, documents and voice notes are fetched with your own token and stored against your organisation only. |
| Rate limiting | Per-IP limits on the API, with stricter limits on sign-in and registration to blunt brute force. |
| Backups | Database backups are taken before every schema change and kept off the application server. |
| Hosting | Indian business data on a dedicated server, administered by Techsaar. No sub-processor resells your conversations. |
Nothing about SaarFlow is designed to make leaving difficult. Ask and you get your contacts, conversations and CRM records in a machine-readable form; ask and they are removed.
If you believe you have found a security problem in SaarFlow, write to support@techsaar.com with enough detail to reproduce it. We will acknowledge within two working days and tell you what we are doing about it.
Please do not test against another customer's account or data. We will not pursue anyone who reports a genuine issue in good faith.
We would rather answer it properly before you buy than be asked about it after an incident. Send the document and we will fill it in.
Techsaar · Indore, Madhya Pradesh · Mon–Sat, 10am–7pm IST