Security
Where your data lives, and who can see it.
No security theatre and no certificate logos we have not earned. This is what is actually true, including the parts we have not built yet.
How we handle data
Your data is separate from everyone else's
Every business on Aura or Hella has its own space. Queries are scoped to your organisation, so another customer's account cannot read your contacts, your conversations or your catalogue even by accident.
This is enforced in the database layer, not by remembering to add a filter in each screen. A missing filter is the way this normally goes wrong.
People see only what their role allows
You decide who gets what. A sales person can see the conversations assigned to them. A manager can see the team. An owner can see everything and can change who has access.
In Aura, editing and publishing are separate permissions. Someone can prepare a campaign without being able to put it live.
What we can and cannot see
We can see your data when you ask us to help with something, and when we are investigating a fault you have reported. That access is logged.
We do not read your customer conversations for any other reason. We do not use your content to train models for other customers. We do not sell or share your contact lists.
If you would rather we did not access your account at all during a support request, say so and we will work from what you can tell us instead. It is slower, and sometimes that trade is worth it.
Where it runs
Servers are in India, which keeps your pages fast for Indian visitors and keeps the data close to home.
Backups run automatically and are kept encrypted. Connections use TLS. Passwords are stored hashed, never in a form anyone here can read.
Every change is written down
Both products keep an audit trail: who did what, to what, and when. This exists because we sell human approval as a feature, and a feature like that is worth nothing if you cannot check afterwards that it happened.
You can see your own audit trail. You do not have to ask us for it.
WhatsApp specifically
Hella runs on the official WhatsApp Business Platform, as a Meta Authorised Tech Provider. Message content passes through Meta's systems under their terms, which apply to every provider on the platform including us.
Bulk messages go out through templates Meta has approved. That is the mechanism that keeps your number in good standing.
What we do not have
The gaps, stated.
- We do not hold ISO 27001 or SOC 2 today. If a certificate is a requirement for you, tell us and we will be straight about where we are rather than implying we have one.
- We are not a payment processor and we do not store card numbers. Payments in anything we build go through a licensed gateway.
- There is no formal bug bounty programme yet. If you find something, email admin@shankhlabs.com and we will treat it seriously and credit you.
Questions your IT team wants answered?
No pressure and no obligation. If we are not the right fit, we will say so.

