WhatsAppOfficial WhatsApp Business API
MetaMeta Tech Partner

Security & Compliance

Enterprise-grade security by default.

Boomly runs on official Meta and Google APIs, encrypts tokens at rest, and never touches your social passwords. Every control below is live in production — not a roadmap promise.

AES-256
Token encryption at rest
TLS
Encrypted in transit
Official
Platform APIs only
99.9%
Target uptime SLA

Official Meta Tech Provider — 100% Safe & Compliant

BoomlyMeta Tech Provider
YouTubeYouTubeOfficial Google API v3

Built using official Meta & Google APIs to keep your accounts protected and fully compliant — no risk of shadowbans or restrictions.

Defense in depth

Security at every layer

From how you sign in to how messages leave our servers — each layer has its own controls.

  1. LAYER 01

    Access

    Official OAuth only — no password sharing. Sessions can be revoked instantly; suspicious logins are rate-limited.

  2. LAYER 02

    Data

    Tokens encrypted with AES-256-GCM. Passwords hashed with bcrypt. Every account is scoped to its owner — no cross-tenant reads.

  3. LAYER 03

    Platform

    Instagram, WhatsApp, Messenger, Telegram and YouTube via documented APIs — no scraping, bots, or browser hacks.

  4. LAYER 04

    Operations

    Webhook signature checks, SSRF guards on outbound calls, CSP headers, and monitored infrastructure with automated backups.

How we protect your data

Encryption, access & platform safety

Each control maps to shipped code — inspectable, auditable, and enforced server-side.

AES-256-GCM token encryption

Connected-account access and refresh tokens are encrypted at rest with a unique IV and auth tag per value. Plaintext tokens never touch the database in production.

Encrypted in transit (TLS)

Every request runs over HTTPS/TLS. Your data and your customers’ conversations never travel the network in the clear.

Passwords hashed with bcrypt

Account passwords are salted and hashed with bcrypt (cost 12) and compared in constant time. We never see, log, or recover your raw password.

Official OAuth — no passwords shared

Connect through Meta and Google’s official OAuth. Revoke Boomly’s access from your platform settings or our dashboard at any time.

Rate limiting & abuse protection

Login, sign-up, OTP, messaging and API endpoints are rate-limited to shut down credential stuffing, spam and cost abuse before it starts.

Official platform APIs only

Built entirely on Meta and Google’s official APIs — no scraping, no bots, no browser extensions. That keeps accounts clear of shadowban or ban risk.

Verified webhooks

Inbound Meta webhooks are signature-verified. Outbound customer webhooks use HMAC signatures and SSRF guards so callbacks cannot reach private networks.

Tenant isolation

Every query is scoped to the authenticated user’s workspace. Organization-owned resources cannot be accessed by ID alone — ownership is checked server-side.

Reliable infrastructure

Deployed on monitored cloud infrastructure with redundancy, automated backups and a 99.9% uptime target so your automations stay online.

Responsible automation

We will never send unsolicited messages.

Every Boomly message is triggered by an explicit user action — a comment, a story reply, an inbound DM or a campaign you configure. Hard limits in code keep accounts inside platform safety thresholds.

Per-account 16,800 DM/day cap

Hard ceiling enforced in our automation worker. Dispatch stops automatically before Meta’s daily-send threshold so your account never enters the rate-limit warning zone.

Self-account loop guard

If a connected account comments on its own post, Boomly skips the automated reply. Prevents accidental self-spam loops that burn API quota.

Respects messaging windows

Outside Meta’s allowed messaging window we fall back to approved message tags or refuse to send. No unauthorised follow-ups.

No scraping or automation hacks

Only documented Graph API and WhatsApp Business API endpoints — never unofficial mobile-app routes, headless browsers or third-party data brokers.

You stay in control

It's your account and your data. Connect on your terms, and leave whenever you want.

Disconnect anytime

Revoke Boomly’s access to any connected account in one click — stored tokens are deleted immediately.

Manage connections

Delete your data

Request full deletion of your account and associated data whenever you choose.

Data deletion

Privacy policy

Read exactly what we collect, why, and how long we keep it — in plain language.

Read privacy policy

Found a vulnerability? Responsible disclosures are always welcome — reach us via the contact page.

Start with confidence. Your account stays yours.

Connect with official OAuth, automate on platform-approved APIs, and disconnect whenever you want. No credit card required on the free plan.