Legal

Security

Last updated 7 September 2026

ValueText writes every conversation into your own Salesforce organisation rather than a separate ValueText database. This page sets out where message data lives, what protects it, the certification we hold, and how to reach us about a security question.

In plain language
  • Your conversations are written as records in your own Salesforce organisation, not a separate ValueText database. Every message is encrypted by default.
  • If you turn on the delete-after-send setting, the message body is held in an encrypted state for under a minute for delivery, then passed to the network provider and cleared, so nothing sits in long-term storage.
  • ValueText Private Limited holds an active ISO/IEC 27001:2022 certificate, IN/81026748/9714, valid to 26 July 2029. We do not hold a SOC 2 report.

This page describes the product as built. The binding commitments are in the Data Processing Addendum and the Terms of Service.

01Where message data lives

Your conversations are written as records in your own Salesforce organisation, not a separate ValueText database. Every message is encrypted by default. If you turn on the delete-after-send setting, the message body is held in an encrypted state for under a minute for delivery, then passed to the network provider and cleared, so nothing sits in long-term storage.

ValueText's own infrastructure is hosted on Amazon Web Services, which provides physical and environmental security controls. Production environments are segregated from development and testing environments, and network security includes firewalls and intrusion detection.

Your Salesforce organisation is held by Salesforce under your own agreement with Salesforce. Incidents affecting your Salesforce environment that are not caused by ValueText fall under that relationship, as set out in Section 9.4 of the Data Processing Addendum.

02ISO 27001:2022

ValueText Private Limited holds an active ISO/IEC 27001:2022 certificate for its information security management system, covering the ValueText product itself.

FieldValue
StandardISO 27001:2022
Certificate no.IN/81026748/9714
HolderValueText Private Limited
Issued27 July 2026
Valid until26 July 2029
Surveillance audits due27 June 2027 and 27 June 2028
Certifying bodyICV Assessments Pvt. Ltd. (EGAC accredited, CAB 011907A)
Verifyhttps://www.icvassessments.com

Scope: Design, development, delivery and support of Salesforce-native multi-channel messaging software (SMS, WhatsApp, Telegram and voice communication solutions) including cloud-based SaaS services, customer support and related services, per the ISMS Statement of Applicability VPL/SOA/01.

ValueText does not hold a SOC 2 report. Where a security questionnaire asks for one, the ISO/IEC 27001:2022 certificate above is what we can evidence.

03Encryption

Message content is encrypted by default, for every message.

  • Data in transit is encrypted using industry-standard protocols (TLS 1.2 or higher).
  • Authentication tokens are stored using cryptographic hashing.

These are the measures committed in Annex 1 of the Data Processing Addendum, which is the binding version of this section.

04Message body discard

An optional setting in Security Settings clears a message's body after it sends. With it on, ValueText processes the message in Pass-Through Mode and keeps no copy of its content.

  • Messages processed in Pass-Through Mode are held only in memory or in transient queues for the duration of delivery processing.
  • Messages are deleted within 60 seconds of processing completion, with no backups or archives created.
  • No persistent storage of message content occurs in Pass-Through Mode.

ValueText's backup and disaster recovery procedures cover its own operational systems and do not include customer personal data, because customer personal data is not persistently stored on ValueText infrastructure.

05Access control

Because the records live in your own Salesforce organisation, access to your conversations follows the permissions already set on that organisation. ValueText adds no separate permission model of its own over them.

ValueText personnel

  • Personnel access to ValueText systems is governed by role-based access controls and the principle of least privilege.
  • Access to your Salesforce organisation is granted only where you have explicitly authorised it for specific support, onboarding, or configuration purposes, and is limited to the duration and scope of that authorisation.
  • Access privileges are reviewed and revoked promptly on personnel role changes or departure.
  • ValueText personnel are bound by written confidentiality obligations and receive training on data protection responsibilities.

06Business Associate Agreements

ValueText Private Limited signs Business Associate Agreements, on ValueText's own paper. To request one, email support@valuetext.io.

The agreement is written for Pass-Through Mode: ValueText contracts as a business associate that transmits ePHI, and does not rely on the conduit exception at 45 CFR 160.103. It sets out the safeguards that apply to that transmission and covers the subcontractors in the path.

Signing a Business Associate Agreement is not a certification. ValueText does not claim HIPAA compliance or HIPAA certification, and no ValueText surface should be read as making that claim.

07Vulnerability disclosure

Report a suspected vulnerability, or ask a security question, at support@valuetext.io. It is the one published address for both.

Reports are logged, investigated, and reviewed under ValueText's documented incident response procedure. Where a report involves customer personal data, the notification obligations in the next section apply.

08Incident response

ValueText will notify you without undue delay, and in any event within 72 hours, after becoming aware of a confirmed personal data breach affecting your personal data.

The notification will, to the extent the information is available at the time, describe:

  • the nature of the breach, including the categories and approximate number of data subjects and records affected;
  • the likely consequences of the breach;
  • the measures taken or proposed to address it and mitigate its effects.

This section summarises Section 9 of the Data Processing Addendum, which is the binding version and states the obligation in full.

Questions about this document support@valuetext.io ValueText Private Limited, Tower B, 8-4-300/1/A, Flat No. 103, Kalpataru Residency, Sanathnagar, Erragadda Sub Post Office, Erragadda, Hyderabad, Telangana 500018, India