Security & ethics

Trust is a requirement.

Vexora Labs builds digital infrastructure. That implies responsibility. This page explains boundaries, basic practices, and how we protect your information without inventing certifications.

What we do NOT do

  • Hacks, exploits, doxxing, phishing, or unauthorized access.
  • Spam, scraping without consent, or unsolicited bulk messaging.
  • Policy bypass (WhatsApp/Discord/hosting/providers).
  • Social engineering to obtain access.

If a request implies harm, abuse, or illegality, we refuse it and propose legitimate alternatives.

Privacy (simple and honest)

  • We keep the minimum needed to quote and support you (name, contact, brief).
  • We don’t sell your information.
  • We share data only if needed to operate (e.g., WABA provider) and with your knowledge.
  • We prefer temporary access and least privilege.

If you need specific requirements (NDA, retention, permissions), we define them in writing.

WhatsApp + AI (compliant practices)

  • We recommend WhatsApp Business API via an authorized provider.
  • Consent-based flows, opt-out, and human handoff when needed.
  • AI-assisted replies with guardrails (what to say / what not to say).
  • Metrics to control quality, not only volume.

Operational best practices

  • Delivery checklist and validation.
  • Backups and test restores (when applicable).
  • Auditable logs for communities (Discord) and controlled changes.
  • Documentation and runbooks to operate without depending on us.

If your project is sensitive, even better.

We define permissions, access, and boundaries from day one. Security is not a “phase” — it’s the baseline.