Security and reliability
Built to keep every message yours
Verification codes and customer messages deserve care. This is how SMSRay protects your account, your data and the people you message, and how to reach us if you find a problem.
stored api key
sha256: 9f2c…a71e
webhook verified
t=… v1=… ±300 s
Data protection
Secrets are hashed, sessions are sealed
We design so that the most sensitive things, keys, codes and tokens, are never stored in a form anyone could reuse.
API keys stored as hashes
A key is shown once when you create or rotate it. We keep only its hash, so a key can be checked but never read back, by anyone.
OTPs stored as hashes
Verification codes are kept as SHA-256 hashes, expire after 5 minutes and show as “(OTP hidden)” in logs and the dashboard.
httpOnly sessions
Dashboard sessions live in Secure, httpOnly, SameSite cookies. Your browser’s scripts never see the tokens.
Rotating refresh tokens
Every refresh issues a new token. If an old one is replayed, we treat it as theft: that session is revoked and the event is audited.
Signed webhooks
Each event carries an HMAC-SHA256 signature over a timestamp and the raw body, checked within ±300 s. Secrets rotate without downtime.
Least-privilege roles
Members can read and send; only owners manage keys, webhooks and teammates. Another workspace’s data simply doesn’t exist for you.
Audit log
Every change made in the dashboard is recorded with who made it, when, from which IP and browser. Field names are logged, values are not.
Passwordless sign-in
Sign in with a one-time code to your phone or email. There is no password to reuse, phish or leak.
Verify every event
Prove a webhook came from us
Check the x-lacspace-signature header before you trust a payload. It takes a dozen lines.
- Signature = HMAC-SHA256(secret, timestamp + "." + raw body)
- Reject anything older or newer than ±300 s to block replays
- During secret rotation, two v1 signatures are sent; accept either
- Compare in constant time, as the samples do
import crypto from "node:crypto";
// x-lacspace-signature: t=<unix>,v1=<hex>[,v1=<hex during secret rotation>]
export function verifySmsrayWebhook(rawBody, header, secret, toleranceSec = 300) {
const pairs = header.split(",").map((p) => p.split("="));
const t = Number(pairs.find(([k]) => k === "t")?.[1]);
if (!t || Math.abs(Date.now() / 1000 - t) > toleranceSec) return false;
const expected = Buffer.from(
crypto.createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex"), "hex");
return pairs
.filter(([k]) => k === "v1")
.some(([, v]) => {
const sig = Buffer.from(v, "hex");
return sig.length === expected.length && crypto.timingSafeEqual(sig, expected);
});
}Template · order_shipped · transactional
- Message type matches your plan
- Sender clearly identified
- No misleading or prohibited content
Message safety
Spam stops before it is sent
Every custom message uses a template approved by SMSRay. Review keeps phishing and spam off Nepal's networks, which protects deliverability for every sender on the platform, including you.
Approved templates
Custom messages are sent from templates our team has approved. We aim to review new templates within one business day.
Built-in OTP template
Codes sent through the OTP API use our own reviewed template, so verification works from day one with nothing to submit.
Abuse limits on OTP
Codes are capped at 3 per 10 minutes for each number across all SMSRay customers. Attempt caps and optional per-IP limits stop SMS pumping.
Report abuse
Received a message you didn't ask for? Write to abuse@lacspace.com. We can withdraw templates and suspend senders who break the rules.
Starter and Business plans send OTP and transactional SMS. Promotional SMS is available on Enterprise, with approved templates.
Infrastructure
- TLS on every connection: the website, the dashboard and the API
- HSTS so browsers refuse to connect over plain HTTP
- Dashboard requests go server to server; tokens never reach the browser
- Error responses never include stack traces or internal details
- Separate rate limits for sign-in, the dashboard and the API
Reliability
- Idempotency-Key on every POST: replays for 24 h never send twice
- Leases on routing and webhooks, so no two workers act on one message
- Smart routing with automatic retries; a message that finally fails is credited back
- Webhooks retried 8 times with backoff, never twice per status
- Background jobs safe to run across several servers
Responsible disclosure
Found a security issue? Tell us first.
Email security@lacspace.com with what you found, how to reproduce it and what you think the impact is. We read every report and will keep you posted as we fix it.
- Test only against your own account and workspace
- Don’t access, change or delete other people’s data
- Don’t send SMS to numbers you don’t own, and don’t run denial-of-service tests
- Give us reasonable time to fix the issue before sharing it publicly
Privacy
We process phone numbers and message content only to deliver your messages and run the service. Your workspace’s data is visible only to your workspace. Our privacy policy explains what we collect, why, and your rights.
A note on certifications
SMSRay does not currently hold third-party security certifications. This page describes the controls we have built. If your review needs more detail, write to security@lacspace.com.
Send with confidence
Hashed keys, signed webhooks and approved templates, on every plan from day one.
Already a customer? Log in