Security and privacy
Your DMs stay yours.
A Telegram session is the key to a real account, and your DMs are your relationships. Hilsen is built around protecting both, with the rules enforced by the database rather than the interface.
What Hilsen protects, and how
- Telegram sessions
- AES-256-GCM, server only
- Calendar, integration and AI keys
- AES-256-GCM, never sent back
- Hilsen API keys
- Stored as SHA-256 hashes
- Telegram two-step passwords
- Never stored
- Synced DMs
- Owner only, enforced by Postgres
The basics
Six things built in from the start
Private by default
Synced chats are visible only to the person who connected the account. Every table that holds them checks the owner in a row-level security policy, including the API paths.Encrypted secrets
Telegram sessions, calendar and integration credentials and AI keys are encrypted with AES-256-GCM, kept in tables browsers can’t reach, and never sent back.Two-factor sign-in
Authenticator-app codes. A password-only session for someone with 2FA sees no workspace data at all, even through the API directly.Four roles
Owner, admin, manager and member. Account limits, exports, integrations and keys are gated by role, in the database.Isolated workspaces
Every row belongs to one workspace. Browser queries go through row-level security, and background jobs scope every query to the workspace.Audit log
Account connects, limit changes, exports, role changes, API keys, AI key changes and Autopilot sends are recorded. Managers can export it.
Roles
Enforced by the database, not the interface
Each rule is checked by Postgres, so calling the API directly doesn’t get around it. The full role matrix is covered by 85 automated checks.
| Capability | Member | Manager | Admin | Owner |
|---|---|---|---|---|
| Read the CRM, Inbox and campaigns | Allowed | Allowed | Allowed | Allowed |
| Reply, build and launch campaigns | Allowed | Allowed | Allowed | Allowed |
| Change account limits and windows | Not allowed | Allowed | Allowed | Allowed |
| Read and export the audit log | Not allowed | Allowed | Allowed | Allowed |
| Delete leads or forget a person | Not allowed | Not allowed | Allowed | Allowed |
| Connect Telegram accounts and integrations | Not allowed | Not allowed | Allowed | Allowed |
| Manage API keys and AI providers | Not allowed | Not allowed | Allowed | Allowed |
| Delete the workspace | Not allowed | Not allowed | Not allowed | Allowed |
Private chats
How synced DMs stay private
Bringing in personal chats is only useful if they stay personal. These rules hold whoever is asking.
- Everything that comes from a synced chat carries its owner: the lead, messages, notes, follow-ups, meetings and drafts.
- Admins can change an account’s sync mode but can’t read its chats.
- API keys and AI agents never see private chats.
- Notifications about a private chat go to its owner only.
- When someone leaves the workspace, their private chats are deleted with them. Chats they shared stay with the team.
Keys and agents
Scoped keys, no send tool
Give an agent exactly the access it needs, and nothing that can message a lead.
- Each API key has scopes: read, write or draft.
- Keys are shown once, stored as hashes and can be revoked any time.
- There is no send tool. Agents create drafts and draft campaigns that a person approves.
Your data
Forget a person everywhere
When someone asks to be forgotten, an admin can remove them from Hilsen and from the tools Hilsen synced them to.
- Forgetting a lead deletes it and removes the copies synced to Notion, Airtable, HubSpot and Google Sheets. Your webhooks are told too.
- Requests to stop are detected in several languages and mark the lead Do not contact.
- Exports and the audit log are available to the roles that need them.
Start with one group link.
Create a workspace, load sample data and run a campaign on simulated accounts before you connect a real one. Free while in beta.