Skip to content

Security and privacy

Your DMs stay yours.

A Telegram session is the key to a real account, and your DMs are your relationships. Hilsen is built around protecting both, with the rules enforced by the database rather than the interface.

What Hilsen protects, and how

Telegram sessions
AES-256-GCM, server only
Calendar, integration and AI keys
AES-256-GCM, never sent back
Hilsen API keys
Stored as SHA-256 hashes
Telegram two-step passwords
Never stored
Synced DMs
Owner only, enforced by Postgres

The basics

Six things built in from the start

  • Private by default

    Synced chats are visible only to the person who connected the account. Every table that holds them checks the owner in a row-level security policy, including the API paths.
  • Encrypted secrets

    Telegram sessions, calendar and integration credentials and AI keys are encrypted with AES-256-GCM, kept in tables browsers can’t reach, and never sent back.
  • Two-factor sign-in

    Authenticator-app codes. A password-only session for someone with 2FA sees no workspace data at all, even through the API directly.
  • Four roles

    Owner, admin, manager and member. Account limits, exports, integrations and keys are gated by role, in the database.
  • Isolated workspaces

    Every row belongs to one workspace. Browser queries go through row-level security, and background jobs scope every query to the workspace.
  • Audit log

    Account connects, limit changes, exports, role changes, API keys, AI key changes and Autopilot sends are recorded. Managers can export it.

Roles

Enforced by the database, not the interface

Each rule is checked by Postgres, so calling the API directly doesn’t get around it. The full role matrix is covered by 85 automated checks.
What each workspace role can do. Enforced by the database.
CapabilityMemberManagerAdminOwner
Read the CRM, Inbox and campaignsAllowedAllowedAllowedAllowed
Reply, build and launch campaignsAllowedAllowedAllowedAllowed
Change account limits and windowsNot allowedAllowedAllowedAllowed
Read and export the audit logNot allowedAllowedAllowedAllowed
Delete leads or forget a personNot allowedNot allowedAllowedAllowed
Connect Telegram accounts and integrationsNot allowedNot allowedAllowedAllowed
Manage API keys and AI providersNot allowedNot allowedAllowedAllowed
Delete the workspaceNot allowedNot allowedNot allowedAllowed

Private chats

How synced DMs stay private

Bringing in personal chats is only useful if they stay personal. These rules hold whoever is asking.
  • Everything that comes from a synced chat carries its owner: the lead, messages, notes, follow-ups, meetings and drafts.
  • Admins can change an account’s sync mode but can’t read its chats.
  • API keys and AI agents never see private chats.
  • Notifications about a private chat go to its owner only.
  • When someone leaves the workspace, their private chats are deleted with them. Chats they shared stay with the team.
How chat sync works

Keys and agents

Scoped keys, no send tool

Give an agent exactly the access it needs, and nothing that can message a lead.
  • Each API key has scopes: read, write or draft.
  • Keys are shown once, stored as hashes and can be revoked any time.
  • There is no send tool. Agents create drafts and draft campaigns that a person approves.

Your data

Forget a person everywhere

When someone asks to be forgotten, an admin can remove them from Hilsen and from the tools Hilsen synced them to.
  • Forgetting a lead deletes it and removes the copies synced to Notion, Airtable, HubSpot and Google Sheets. Your webhooks are told too.
  • Requests to stop are detected in several languages and mark the lead Do not contact.
  • Exports and the audit log are available to the roles that need them.
How AI keys and agents work

Start with one group link.

Create a workspace, load sample data and run a campaign on simulated accounts before you connect a real one. Free while in beta.