Security
Last updated 18 June 2026
Security is part of how we build. This page describes the practical measures we take to protect your data and the automations we run for you. It pairs with our Privacy Policy, which covers what data we collect and why.
1. Data minimisation
We collect as little as possible. Our website enquiry form captures only your name, email, phone, a project description and an indicative budget, and those enquiries are delivered to us over email rather than stored in a public-facing database.
2. Encryption in transit
Our website and the APIs we integrate are served over HTTPS/TLS, so data moving between your browser, our site and our providers is encrypted in transit.
3. Infrastructure
We run on reputable cloud and infrastructure providers with their own strong security programmes, including our website host and our email provider (Resend). Managed automations run on monitored infrastructure we maintain.
4. Access control
Access to client systems and data is granted on a least-privilege, need-to-know basis and limited to the people working on your project. Administrative access is restricted and protected with strong, unique credentials and multi-factor authentication where available.
5. Credentials and secrets
- API keys, tokens and other secrets are stored in secure secret stores and environment configuration, never in client-side code or public repositories.
- For self-hosted engagements, you hold your own keys and credentials — we hand them over and do not retain standing access unless you ask us to support the deployment.
- We connect to WhatsApp and Instagram only through Meta’s official APIs.
6. Monitoring and availability
For Managed engagements we monitor the automations we run and work to keep them available, with uptime monitoring and alerting so we can respond to issues. Specific availability targets, if any, are set in your engagement.
7. Incident response
If we become aware of a security incident that affects your personal data, we will investigate, take steps to contain it, and notify you and any relevant authority as required by the DPDP Act and applicable law.
8. Responsible disclosure
If you believe you have found a security vulnerability in our website or services, please tell us at contact@dmreply.in before disclosing it publicly. We appreciate reports made in good faith and will work with you to verify and fix genuine issues.
9. Your part
Security is shared. Please keep your own accounts (WhatsApp Business, Instagram, email and any dashboards we provide) protected with strong passwords and multi-factor authentication, and let us know promptly if you suspect any compromise.
10. Contact
Security questions or concerns? Email contact@dmreply.in.
This page explains our current practices in plain language. It is provided for transparency and is not legal advice. Please have it reviewed by your own legal counsel before relying on it. Questions? Email contact@dmreply.in.
