Security
How NinzaSMS protects your data, API keys, and communications.
At NinzaSMS, security is a core part of our platform. We implement industry-standard security controls to protect your account, data, and communications.
This page explains the security controls that are actually implemented on our platform. We do not make unverified security claims.
Security Controls
Implemented security measures on our platform.
HTTPS / TLS
All traffic to and from our platform is encrypted using TLS 1.2 and TLS 1.3. HTTP requests are automatically redirected to HTTPS.
API Key Security
API keys are generated using cryptographically secure methods, hashed before storage, and can be rotated or revoked at any time from your dashboard.
Password Hashing
All user passwords are hashed using modern, industry-standard hashing algorithms. Plain-text passwords are never stored.
Account Security
Accounts are protected by secure authentication. Users are encouraged to use strong, unique passwords and keep their credentials private.
Access Control
Internal systems are protected by strict access controls. Only authorized personnel have access to production systems, and access is logged.
Data Retention
Personal and transactional data is retained only as long as necessary for service delivery, legal compliance, or dispute resolution.
Incident Response
We maintain a defined process for detecting, responding to, and reporting security incidents. Affected users are notified as required by applicable law.
Infrastructure
Our infrastructure is hosted on reputable cloud providers with physical, network, and environmental security controls.
Data Protection
-
Encryption in Transit: All data transmitted between your systems and ours is encrypted using TLS.
-
Access Logging: Access to sensitive systems is logged and monitored for unusual activity.
-
Least Privilege: Employees and systems are granted only the minimum access required to perform their functions.
-
Data Minimization: We collect only the data necessary to provide our services.
-
Third-Party Processors: We work only with reputable service providers who meet our security standards.
Account Security Tips
Best practices to keep your account secure.
Use Strong Passwords
Use a unique password with a mix of letters, numbers, and symbols.
Keep API Keys Private
Never share your API keys publicly or commit them to code repositories.
Rotate Keys Regularly
Rotate your API keys periodically to reduce the risk of compromise.
Watch for Phishing
We never ask for your password or API keys via email or chat.
Report a Security Issue
If you believe you have found a security vulnerability or have a security concern, please report it to us immediately. We take all reports seriously.