Check out our Launch week free trial and the Polymorfa Builders Program! 15 Pro numbers + add-ons for 30 days.

Ends in ––d : ––h : ––m : ––s

Command Palette

Search for a command to run...

Security

Secure by default.

HMAC-signed webhooks, 21-scope keys, compliance logging, and automatic key scanning: the boring parts, done properly.

Trust

Compliance built in.

HMAC-signed webhooks, role-scoped keys, and a full audit trail are on from the first request. GDPR and LGPD aren't checkboxes: residency, purge guarantees, and processor agreements are part of the product.

GDPREU data protection
LGPDLei Geral, Brazil
HMAC-signed webhookson by default
Role-scoped API keys21 scopes
Compliance logging365-day retention
Key scanningauto-revoke on leak
Residency

Data lives where it should.

One rule, applied per data class: your data lives in the nearest jurisdiction (Brazil, India, or Switzerland), while the console account, configuration, and secrets stay central in Switzerland.

Switzerland
Console & secrets

The console account, configuration, settings, and secrets. Stored in Switzerland under Softium LLC, for every user.

In-jurisdiction · Brazil
Hosted Message Storage

Brazilian users' chats, media, and contacts are stored on Brazilian infrastructure, LGPD-native.

In-jurisdiction · India
Accounts & auth data

Account and auth data live in the nearest jurisdiction: India stays in India, Brazil in Brazil, everyone else in Switzerland.

Access

Keys that can't do more than they should.

21 scopes per key, checked before anything executes, and every sensitive action lands in an exportable audit trail. Leaked keys revoke themselves.

pm_live_····4f2k4 of 21 scopes
messages:sendmessages:readsessions:managewebhooks:managecampaigns:runstorage:exportkeys:rotatecalls:answer
This key can hold a conversation. It cannot blast a campaign, export storage, or mint new keys.
Audit log365-day retention
14:02key.createdrajeh@softium.ch · console4 scopes
14:07webhook.replayedconsole · project spring-launch1 event
15:11storage.purgedAPI · +55 550-0142verified
16:40key.revokedsecret scanner · leaked in CI logsauto
Deep dive

Boring, audited, on by default.

Every webhook is HMAC-signed, every key is scoped, every admin action lands in a 365-day log. There is nothing to enable.

GDPR and LGPD aren't checkboxes: data residency, purge guarantees, and processor agreements are part of the product, hosted in Switzerland.

21
key scopes
365 days
audit retention
2
regimes: GDPR · LGPD
How it works

A request's paper trail.

Every call leaves the same three marks.

1
SignedHMAC on every webhook; verify with one SDK call.
2
Scoped21 key scopes checked before anything executes.
3
LoggedCompliance trail with 365-day retention, exportable.
By the numbers

The security posture.

The boring parts, done properly.

WebhooksHMAC-signed
Key scopes21
Audit log365 days
Key scanningauto-revoke on leak
ComplianceGDPR · LGPD

Ship a WhatsApp integration this afternoon.

Free on the sandbox. No credit card. The projects you start here migrate straight into production.