Security & Compliance
Enterprise-grade security by default.
Boomly runs on official Meta and Google APIs, encrypts tokens at rest, and never touches your social passwords. Every control below is live in production — not a roadmap promise.
- AES-256
- Token encryption at rest
- TLS
- Encrypted in transit
- Official
- Platform APIs only
- 99.9%
- Target uptime SLA
Official Meta Tech Provider — 100% Safe & Compliant

Built using official Meta & Google APIs to keep your accounts protected and fully compliant — no risk of shadowbans or restrictions.
Security at every layer
From how you sign in to how messages leave our servers — each layer has its own controls.
- LAYER 01
Access
Official OAuth only — no password sharing. Sessions can be revoked instantly; suspicious logins are rate-limited.
- LAYER 02
Data
Tokens encrypted with AES-256-GCM. Passwords hashed with bcrypt. Every account is scoped to its owner — no cross-tenant reads.
- LAYER 03
Platform
Instagram, WhatsApp, Messenger, Telegram and YouTube via documented APIs — no scraping, bots, or browser hacks.
- LAYER 04
Operations
Webhook signature checks, SSRF guards on outbound calls, CSP headers, and monitored infrastructure with automated backups.
Encryption, access & platform safety
Each control maps to shipped code — inspectable, auditable, and enforced server-side.
AES-256-GCM token encryption
Connected-account access and refresh tokens are encrypted at rest with a unique IV and auth tag per value. Plaintext tokens never touch the database in production.
Encrypted in transit (TLS)
Every request runs over HTTPS/TLS. Your data and your customers’ conversations never travel the network in the clear.
Passwords hashed with bcrypt
Account passwords are salted and hashed with bcrypt (cost 12) and compared in constant time. We never see, log, or recover your raw password.
Official OAuth — no passwords shared
Connect through Meta and Google’s official OAuth. Revoke Boomly’s access from your platform settings or our dashboard at any time.
Rate limiting & abuse protection
Login, sign-up, OTP, messaging and API endpoints are rate-limited to shut down credential stuffing, spam and cost abuse before it starts.
Official platform APIs only
Built entirely on Meta and Google’s official APIs — no scraping, no bots, no browser extensions. That keeps accounts clear of shadowban or ban risk.
Verified webhooks
Inbound Meta webhooks are signature-verified. Outbound customer webhooks use HMAC signatures and SSRF guards so callbacks cannot reach private networks.
Tenant isolation
Every query is scoped to the authenticated user’s workspace. Organization-owned resources cannot be accessed by ID alone — ownership is checked server-side.
Reliable infrastructure
Deployed on monitored cloud infrastructure with redundancy, automated backups and a 99.9% uptime target so your automations stay online.
We will never send unsolicited messages.
Every Boomly message is triggered by an explicit user action — a comment, a story reply, an inbound DM or a campaign you configure. Hard limits in code keep accounts inside platform safety thresholds.
Per-account 16,800 DM/day cap
Hard ceiling enforced in our automation worker. Dispatch stops automatically before Meta’s daily-send threshold so your account never enters the rate-limit warning zone.
Self-account loop guard
If a connected account comments on its own post, Boomly skips the automated reply. Prevents accidental self-spam loops that burn API quota.
Respects messaging windows
Outside Meta’s allowed messaging window we fall back to approved message tags or refuse to send. No unauthorised follow-ups.
No scraping or automation hacks
Only documented Graph API and WhatsApp Business API endpoints — never unofficial mobile-app routes, headless browsers or third-party data brokers.
You stay in control
It's your account and your data. Connect on your terms, and leave whenever you want.
Disconnect anytime
Revoke Boomly’s access to any connected account in one click — stored tokens are deleted immediately.
Manage connectionsDelete your data
Request full deletion of your account and associated data whenever you choose.
Data deletionPrivacy policy
Read exactly what we collect, why, and how long we keep it — in plain language.
Read privacy policyFound a vulnerability? Responsible disclosures are always welcome — reach us via the contact page.
Start with confidence. Your account stays yours.
Connect with official OAuth, automate on platform-approved APIs, and disconnect whenever you want. No credit card required on the free plan.