Security
ValueText writes every conversation into your own Salesforce organisation rather than a separate ValueText database. This page sets out where message data lives, what protects it, the certification we hold, and how to reach us about a security question.
- Your conversations are written as records in your own Salesforce organisation, not a separate ValueText database. Every message is encrypted by default.
- If you turn on the delete-after-send setting, the message body is held in an encrypted state for under a minute for delivery, then passed to the network provider and cleared, so nothing sits in long-term storage.
- ValueText Private Limited holds an active ISO/IEC 27001:2022 certificate, IN/81026748/9714, valid to 26 July 2029. We do not hold a SOC 2 report.
This page describes the product as built. The binding commitments are in the Data Processing Addendum and the Terms of Service.
01Where message data lives
Your conversations are written as records in your own Salesforce organisation, not a separate ValueText database. Every message is encrypted by default. If you turn on the delete-after-send setting, the message body is held in an encrypted state for under a minute for delivery, then passed to the network provider and cleared, so nothing sits in long-term storage.
ValueText's own infrastructure is hosted on Amazon Web Services, which provides physical and environmental security controls. Production environments are segregated from development and testing environments, and network security includes firewalls and intrusion detection.
Your Salesforce organisation is held by Salesforce under your own agreement with Salesforce. Incidents affecting your Salesforce environment that are not caused by ValueText fall under that relationship, as set out in Section 9.4 of the Data Processing Addendum.
02ISO 27001:2022
ValueText Private Limited holds an active ISO/IEC 27001:2022 certificate for its information security management system, covering the ValueText product itself.
Scope: Design, development, delivery and support of Salesforce-native multi-channel messaging software (SMS, WhatsApp, Telegram and voice communication solutions) including cloud-based SaaS services, customer support and related services, per the ISMS Statement of Applicability VPL/SOA/01.
ValueText does not hold a SOC 2 report. Where a security questionnaire asks for one, the ISO/IEC 27001:2022 certificate above is what we can evidence.
03Encryption
Message content is encrypted by default, for every message.
- Data in transit is encrypted using industry-standard protocols (TLS 1.2 or higher).
- Authentication tokens are stored using cryptographic hashing.
These are the measures committed in Annex 1 of the Data Processing Addendum, which is the binding version of this section.
04Message body discard
An optional setting in Security Settings clears a message's body after it sends. With it on, ValueText processes the message in Pass-Through Mode and keeps no copy of its content.
- Messages processed in Pass-Through Mode are held only in memory or in transient queues for the duration of delivery processing.
- Messages are deleted within 60 seconds of processing completion, with no backups or archives created.
- No persistent storage of message content occurs in Pass-Through Mode.
ValueText's backup and disaster recovery procedures cover its own operational systems and do not include customer personal data, because customer personal data is not persistently stored on ValueText infrastructure.
05Access control
Because the records live in your own Salesforce organisation, access to your conversations follows the permissions already set on that organisation. ValueText adds no separate permission model of its own over them.
ValueText personnel
- Personnel access to ValueText systems is governed by role-based access controls and the principle of least privilege.
- Access to your Salesforce organisation is granted only where you have explicitly authorised it for specific support, onboarding, or configuration purposes, and is limited to the duration and scope of that authorisation.
- Access privileges are reviewed and revoked promptly on personnel role changes or departure.
- ValueText personnel are bound by written confidentiality obligations and receive training on data protection responsibilities.
06Business Associate Agreements
ValueText Private Limited signs Business Associate Agreements, on ValueText's own paper. To request one, email support@valuetext.io.
The agreement is written for Pass-Through Mode: ValueText contracts as a business associate that transmits ePHI, and does not rely on the conduit exception at 45 CFR 160.103. It sets out the safeguards that apply to that transmission and covers the subcontractors in the path.
Signing a Business Associate Agreement is not a certification. ValueText does not claim HIPAA compliance or HIPAA certification, and no ValueText surface should be read as making that claim.
07Vulnerability disclosure
Report a suspected vulnerability, or ask a security question, at support@valuetext.io. It is the one published address for both.
Reports are logged, investigated, and reviewed under ValueText's documented incident response procedure. Where a report involves customer personal data, the notification obligations in the next section apply.
08Incident response
ValueText will notify you without undue delay, and in any event within 72 hours, after becoming aware of a confirmed personal data breach affecting your personal data.
The notification will, to the extent the information is available at the time, describe:
- the nature of the breach, including the categories and approximate number of data subjects and records affected;
- the likely consequences of the breach;
- the measures taken or proposed to address it and mitigate its effects.
This section summarises Section 9 of the Data Processing Addendum, which is the binding version and states the obligation in full.