Security
Your messages stay yours. Here is exactly where the line sits.
Isolated by construction
Every query on tenant data is automatically scoped to your organization. With no organization in context, queries fail closed instead of returning everything.
Operators see metadata, not messages
Platform staff manage organizations, plans, and usage. Message content is absent from their console entirely, not merely hidden.
The support-session exception, in full
If you report a fault we cannot reproduce, an operator can start a support session as one of your users. It is deliberately loud: the token expires after 30 minutes, every request made with it is marked as impersonation, an orange banner sits above the app for the whole session, and the event lands in your organization’s own audit log naming who started it, when, and why.
Access control inside your team
Owners, managers, and agents see exactly what their role allows. Custom roles give granular permissions beyond admin and agent, per-account access control decides who works which inbox, and chat visibility can hide specific conversations from specific people. Every change your team makes is written to the audit log.
Sessions treated as credentials
Connected Telegram sessions are stored as secrets. Access ends the moment you disconnect an account or remove a teammate.
Reporting a vulnerability
If you believe you have found a security issue, email security@araraa.com. We acknowledge reports quickly, keep you informed, and do not take legal action against good-faith research.