Security Policy
Last updated August 26, 2026
The short version
- Contact details are encrypted. A contact’s name, email address and phone number are stored encrypted, not as plain text.
- Brands are separated in the database itself, not by a filter in the application, so one brand cannot see another’s records.
- Passwords are never stored in readable form, and you can turn on two-step verification yourself.
- Important actions are recorded in an audit trail that is deliberately never cleared, and each entry is linked to the one before it so tampering shows up.
- We hold no security certifications. No SOC 2, no ISO 27001, no HIPAA, no PCI DSS. If a supplier questionnaire asks, that is the honest answer.
- Found a problem? Tell us at [email protected] rather than posting it publicly.
1. What this page is
This describes how QuickGrow AI, a product of CyberCraft Bangladesh, protects the data you keep in it — and what your own responsibilities are. It is a description of practice, not a warranty.
2. Certifications: we hold none
QuickGrow AI is not SOC 2 audited, not ISO 27001 certified, not HIPAA compliant and not PCI DSS certified. We have not been assessed against any of those standards. Anyone telling you otherwise is mistaken.
Practical consequences: do not store health records in QuickGrow AI as if it were a HIPAA-covered system, and do not put card numbers into a contact record or a message. Card and mobile-wallet payments for your own subscription are handled by our payment provider, not by us.
3. Protecting stored data
- Contact first name, last name, email address and phone number are encrypted in the database.
- Credentials for apps you connect are encrypted and are never sent back to your browser, not even to the person who entered them.
- Account passwords are stored one-way scrambled; they cannot be read back, by us or by anyone with database access.
- Two-step verification secrets and recovery codes are stored scrambled, and a recovery code is used up once it is used.
4. Keeping accounts apart
Every brand is a separate tenant, and separation is enforced by the database rather than by application code remembering to filter. This is what makes per-branch or per-client separation genuine rather than cosmetic. Sharing a contact between the brands in your own account is a deliberate action; nothing crosses between different customers.
5. Access control
- Two-step verification with an authenticator app, plus recovery codes, available in your security settings.
- Roles and granular permissions: reading the inbox, writing in the inbox, sending campaigns and exporting contacts are separate permissions.
- API keys are scoped to specific permissions and carry their own rate limit — 1,000 requests a minute per key by default. Treat a key like a password; rotate it if it may have leaked.
- Sign-in sessions can be ended, and expired session records are cleared after 30 days.
6. Audit trail
Significant actions record who did them, when, from which network address and browser, and what changed. Each entry carries a value derived from the entry before it, so an attempt to alter or remove an entry after the fact does not go unnoticed. Audit records are deliberately excluded from the automatic clean-up and are kept indefinitely.
7. Protecting sending
- Before an SMS or WhatsApp message to a contact goes out, the platform checks consent, then quiet hours, then the per-contact frequency cap.
- Every send is also checked against your credit balance before it is dispatched, and a campaign is checked in full before it starts. A send the balance cannot cover is refused rather than queued, so an account cannot spend past what it has paid for.
- Outgoing content is scored against known spam and phishing patterns.
- Account-level spam, bounce and complaint rates and volume spikes are monitored, and sending can be frozen automatically when a threshold is crossed.
- New accounts start with a limited sending capacity that grows with account age and history.
- Requests that the platform makes out to addresses you supply are checked before they are made, so a connector or webhook cannot be pointed at our internal network.
8. Retention and deletion
Messages 365 days, contact activity 180 days, automation run history 90 days, delivery notification records 30 days, expired sessions 30 days; audit records indefinitely. These are platform-wide values set by us, not per-account settings.
Erasing a contact deletes the contact, its messages, its activity and its consent records together in a single operation, and writes an audit entry. There is no self-service erase button today — it is a request you send us.
9. Your side of it
Most account compromises start with a person, not a system.
- Use a password you use nowhere else, and turn on two-step verification.
- Give each team member their own login and only the permissions they need. Remove people the day they leave.
- Never share an API key by message or email, and never put one in front-end code.
- Be careful what you export. A contact export is plain text once it leaves the platform.
10. Reporting a vulnerability
If you believe you have found a security problem, email [email protected] with enough detail to reproduce it. Please do not publish it, and please do not test against another customer’s account or data. We will acknowledge your report and keep you informed while we investigate.
There is no bug bounty programme today.
11. If something goes wrong
If a security incident affects your data, we will investigate, contain it, and tell you what happened and what to do, without undue delay and in line with what the law applicable to your account requires.
12. Changes
This page changes as the platform does. This version is dated 26 August 2026.