Security
Last updated: August 2026
Infrastructure
Hilo is built on specialized infrastructure providers: Xano for the database and backend logic, and Vercel for hosting the web application. Both providers maintain their own security and compliance programs at the infrastructure level.
Encryption in transit
All communication between your browser, the Hilo application, and our providers travels encrypted over HTTPS/TLS.
Isolation between organizations
Each organization (business) using Hilo has its data — contacts, conversations, campaigns, settings — logically isolated from every other: every database query explicitly filters by the authenticated user's organization, so one organization can never see another's data.
Access control
Access within an organization is segmented by role: owner, admin, and agent have different permission levels over settings, team, and data. Passwords are stored as hashes, never in plain text.
Official Meta channels
WhatsApp and Instagram messaging is sent and received through Meta's official APIs (WhatsApp Cloud API and Graph API), not through unofficial methods or third parties not authorized by Meta.
Reporting vulnerabilities
If you find a security vulnerability in Hilo, we appreciate a responsible report before any public disclosure. Reach us at adrian5digo@gmail.com.