Skip to main content

How we protect your data

The safeguards BeeCastly really uses today to protect your account and your customers' data.

Security Features

Security built into BeeCastly

From encrypted credentials to team roles, here is how we keep your data safe.

HTTPS and encrypted credentials

Every page and API call uses HTTPS. Credentials you save in BeeCastly, like SMTP passwords and provider keys, are encrypted with AES-256-GCM.

API key security

API keys are stored as a hash, never in plain text. Create and manage your keys from your dashboard.

Sign-in and team roles

Role-based access for your team: Owner, Admin, Manager, Member, Viewer and Worker. Turn on two-step sign-in for extra protection.

Your data kept separate

Each account's data is kept separate, and every request is checked against the account it belongs to.

Protection against abuse

Rate limits and brute-force protection on sign-in, and reCAPTCHA spam protection on public forms.

Your data, your control

Export your contacts any time, and ask us to delete your data. Opt-outs and unsubscribes are respected in your campaigns.

Privacy tools

Tools that help you respect privacy

BeeCastly gives you tools that help with privacy laws. Following those laws for your own business is still your responsibility.

GDPR Tools

Tools that help you follow the EU GDPR: unsubscribe and opt-out handling, and data export and deletion on request.

European Union

Data export and deletion

Export or delete a contact's data when they ask, which helps with requests under laws like California's CCPA.

California, USA

Opt-out handling

Contacts who opt out or unsubscribe stop getting your campaigns, which helps you respect choices under laws like Brazil's LGPD.

Brazil

Meta's Official Platform

Connect WhatsApp through Meta's official WhatsApp Business Platform (Cloud API) if you prefer, and follow Meta's messaging policies.

Global
Best Practices

What we do today

The practices in place right now to keep your data safe.

HTTPS on every page and API call

AES-256-GCM encryption for saved credentials and provider keys

API keys stored as hashes, never in plain text

Role-based access for team members

Optional two-step sign-in with an authenticator app

Rate limiting and brute-force protection on sign-in

reCAPTCHA spam protection on public forms

Data export and deletion on request

Report a Vulnerability

Found a security issue? Please email [email protected] with the details. We take every report seriously.

All-in-one AI business platform

Start free with BeeCastly

Free forever plan, no card needed.

By subscribing you agree to receive product news from BeeCastly. Unsubscribe anytime. Privacy policy

  • Free plan forever
  • 31 languages
  • Installs like an app