Security Policy – SIYOQ
Last updated on: 20th August 2026
This policy describes the security controls that apply to SIYOQ, the Sioniq business messaging service.
Relationship to our main policy. This policy is specific to SIYOQ and supplements the Sioniq Security Policy, which covers our infrastructure, application, employee and third-party controls generally. Where the two differ in relation to messaging, this policy governs.
Scope
This policy applies to the SIYOQ messaging service, the credentials and business assets a customer connects to it, the message data it processes, and the interfaces through which it communicates with third-party messaging platforms.
General controls covering hosting, network security, application development, employee security, vendor management, backup and disaster recovery are set out in the Sioniq Security Policy and apply to SIYOQ as well.
Service Status
SIYOQ is under development and not yet generally available. The controls in this policy form part of the design of the service and apply from the date it is made available to a customer. Availability is also subject to the approval processes of the applicable messaging platform.
Credential and Token Protection
Customer messaging credentials are among the most sensitive data we hold, because a compromised credential could allow messages to be sent in a customer’s name to that customer’s own customers. Accordingly:
- Messaging account identifiers, access tokens, system user credentials and phone number certificates are stored encrypted in a managed secrets store.
- Credentials are never held in source code, configuration files or logs.
- Credentials are never shared between customers, and one customer’s credentials are never used to send on behalf of another.
- Access is limited to the systems and named personnel that require it to operate the service.
- On disconnection or termination, credentials are revoked and removed from active systems.
Customer Account Ownership
Each customer connects and authorises its own messaging account and registers its own sender number. Sioniq does not operate a shared sender. Access to a customer’s business assets is limited to the permissions that customer has authorised and to what is required to provide the service.
Message Data Handling
- Message content and recipient details are processed only to deliver, display and report on messages the customer has instructed us to send.
- Staff access to message content is restricted to authorised support personnel, granted only where necessary to resolve a request, and logged.
- Message data is logically segregated per customer tenant.
- Message content is not used for advertising and is not sold.
Consent and Suppression Integrity
Consent and opt-out records are treated as controlled data. Suppression lists are protected against being overridden by ordinary application users, and an opt-out recorded against a number suppresses further sends to it across the customer’s account.
Audit Logging
Message sends are logged with the initiating user, template, recipient reference, timestamp and delivery outcome, and made available to the customer. Administrative actions — template changes, permission changes, credential connection and disconnection — are logged separately.
API and Webhook Security
- All communication with third-party platform APIs uses HTTPS/TLS.
- Webhook endpoints used to receive events from third-party platforms authenticate and validate every inbound request and reject unverified payloads.
- API credentials issued to customers are scoped to their own account and can be rotated by the customer.
- Integration activity, including authentication failures and permission changes, is logged and monitored.
Product Separation
Sioniq operates more than one product line, including the JOS ERP platform. Messaging data and messaging credentials are held separately from ERP data, with their own access controls, and are not used to develop, train or improve other Sioniq products beyond what is necessary to deliver the messaging service the customer has requested.
Encryption and Key Handling
Data in transit is encrypted using TLS. Data at rest is encrypted using industry-standard algorithms where applicable to the deployment. Encryption keys are managed through the key management services of our cloud provider, with access restricted to authorised personnel.
Access Control
Access to messaging systems follows role-based access control and the principle of least privilege. Administrative access to production is restricted to named personnel and logged. Within the application, customers control which of their own staff can send messages, read conversations, edit templates and view reports.
Incident Response
- Security incidents are logged, triaged by severity and investigated, with evidence preserved.
- Where an incident falls within the categories specified by the Indian Computer Emergency Response Team (CERT-In) under its Directions of 28 April 2022, we report it to CERT-In within six (6) hours of becoming aware of it.
- Where a personal data breach requires notification under the Digital Personal Data Protection Act, 2023, we notify the Data Protection Board of India and affected individuals as required.
- Affected customers are notified without undue delay and within the period required by applicable law, with the information reasonably needed to assess and respond.
- Where an incident affects messaging credentials, those credentials are revoked and the customer is asked to reconnect.
Retention and Disposal
System logs are retained for 180 days and maintained within India, in accordance with the CERT-In Directions of 28 April 2022. Message data is retained as set out in the SIYOQ Privacy Policy and deleted on request within thirty (30) days. Data is securely erased or rendered irrecoverable at the end of its retention period.
Customer Responsibilities
Security of the messaging channel is shared. Customers are responsible for:
- Protecting access to their messaging account, sender number and any API credentials issued to them, and rotating credentials if exposure is suspected.
- Provisioning and promptly deprovisioning their own users, and setting appropriate roles and permissions.
- Ensuring only authorized staff can send messages in the business’s name.
- Obtaining and recording consent before messaging a recipient, and honoring opt-outs.
- Notifying us promptly at security@sioniq.com of any suspected compromise.
For messaging data relating to a customer’s own customers, Sioniq acts as a Data Processor and the customer acts as the Data Fiduciary. Sioniq does not determine the lawfulness of communications a customer chooses to send.
Assurance
On request and under an appropriate confidentiality agreement, we will provide reasonable information about our security controls, including responses to a security questionnaire. Customer-conducted penetration testing of our production environment requires our prior written consent and a scope agreed in advance.
Security Contact
For security matters, including reporting a suspected vulnerability or security incident, contact security@sioniq.com. Please do not publicly disclose a suspected vulnerability before we have had a reasonable opportunity to address it.
Sioniq Tech Private Limited, 8-2-293/82/A/1107, Plot No. 1107, Road No. 55, Jubilee Hills, Hyderabad, Telangana 500 033, India. Phone: 040 69 888 999.