HiAlly Security & Data Protection
Last updated 26 September 2026
This page describes the security measures HiAlly has in place today. We only list what we actually do. Our connected services are in development, and this page will change as they do.
Local products keep your data on your computer by default
Billing Books and Assistant process your business data on your own computer. The only thing they send us is your licence check, with the details you typed when you activated. Billing Books chains its records with a cryptographic hash, so if an entry is altered or removed afterwards, the chain no longer verifies. Backups, if you turn them on, go to a folder you choose, in your own account. If you set up an optional online AI feature, the text it needs goes to the provider you chose, as our Privacy Policy explains.
Connections are encrypted in transit
This website and our licence service are served over HTTPS. Messages from Meta reach our connected service over HTTPS, and our replies to Meta and Telegram are sent over HTTPS.
Every WhatsApp delivery is checked
Meta signs every message it delivers to us. HiAlly checks that signature against the exact message received before doing anything with it, and rejects any delivery that fails the check. The business a message belongs to is worked out from the connected number in Meta’s signed data — never from anything a sender can type.
Each business is kept separate
Each business’s conversations and enquiries are stored in a separate database file, and each connected WhatsApp number can belong to only one business on HiAlly.
Sign-in and access
- Passwords are stored only as salted scrypt hashes, never as the password itself.
- Sign-in sessions use HttpOnly cookies and expire after 30 days.
- Team members see what their role allows, and some settings — such as connecting a business system — can only be changed by the account owner.
Credentials
Access tokens and keys a business gives HiAlly are used only to talk to the service they belong to, and are shown on HiAlly’s screens only in a shortened, masked form.
What customers are told
HiAlly Sales does not give prices, stock levels or account balances to a customer it has not identified; that information goes only to the business’s own team. When HiAlly cannot answer something, it says so and passes the conversation to a person, rather than guess.
Certifications
HiAlly does not currently hold security certifications such as SOC 2 or ISO 27001. We will only list a certification here once it has been awarded.
Deleting data
How to ask us to delete data is explained on our Data Deletion page.
Reporting a security issue
If you believe you have found a security problem, email hello@hially.in with the subject “Security” and as much detail as you can. Please do not access or change data that is not yours while investigating.