Skip to content
SMSRay

Security and reliability

Built to keep every message yours

Verification codes and customer messages deserve care. This is how SMSRay protects your account, your data and the people you message, and how to reach us if you find a problem.

Data protection

Secrets are hashed, sessions are sealed

We design so that the most sensitive things, keys, codes and tokens, are never stored in a form anyone could reuse.

API keys stored as hashes

A key is shown once when you create or rotate it. We keep only its hash, so a key can be checked but never read back, by anyone.

OTPs stored as hashes

Verification codes are kept as SHA-256 hashes, expire after 5 minutes and show as “(OTP hidden)” in logs and the dashboard.

httpOnly sessions

Dashboard sessions live in Secure, httpOnly, SameSite cookies. Your browser’s scripts never see the tokens.

Rotating refresh tokens

Every refresh issues a new token. If an old one is replayed, we treat it as theft: that session is revoked and the event is audited.

Signed webhooks

Each event carries an HMAC-SHA256 signature over a timestamp and the raw body, checked within ±300 s. Secrets rotate without downtime.

Least-privilege roles

Members can read and send; only owners manage keys, webhooks and teammates. Another workspace’s data simply doesn’t exist for you.

Audit log

Every change made in the dashboard is recorded with who made it, when, from which IP and browser. Field names are logged, values are not.

Passwordless sign-in

Sign in with a one-time code to your phone or email. There is no password to reuse, phish or leak.

Verify every event

Prove a webhook came from us

Check the x-lacspace-signature header before you trust a payload. It takes a dozen lines.

  • Signature = HMAC-SHA256(secret, timestamp + "." + raw body)
  • Reject anything older or newer than ±300 s to block replays
  • During secret rotation, two v1 signatures are sent; accept either
  • Compare in constant time, as the samples do
import crypto from "node:crypto";

// x-lacspace-signature: t=<unix>,v1=<hex>[,v1=<hex during secret rotation>]
export function verifySmsrayWebhook(rawBody, header, secret, toleranceSec = 300) {
  const pairs = header.split(",").map((p) => p.split("="));
  const t = Number(pairs.find(([k]) => k === "t")?.[1]);
  if (!t || Math.abs(Date.now() / 1000 - t) > toleranceSec) return false;
  const expected = Buffer.from(
    crypto.createHmac("sha256", secret).update(`${t}.${rawBody}`).digest("hex"), "hex");
  return pairs
    .filter(([k]) => k === "v1")
    .some(([, v]) => {
      const sig = Buffer.from(v, "hex");
      return sig.length === expected.length && crypto.timingSafeEqual(sig, expected);
    });
}

Message safety

Spam stops before it is sent

Every custom message uses a template approved by SMSRay. Review keeps phishing and spam off Nepal's networks, which protects deliverability for every sender on the platform, including you.

Approved templates

Custom messages are sent from templates our team has approved. We aim to review new templates within one business day.

Built-in OTP template

Codes sent through the OTP API use our own reviewed template, so verification works from day one with nothing to submit.

Abuse limits on OTP

Codes are capped at 3 per 10 minutes for each number across all SMSRay customers. Attempt caps and optional per-IP limits stop SMS pumping.

Report abuse

Received a message you didn't ask for? Write to abuse@lacspace.com. We can withdraw templates and suspend senders who break the rules.

Starter and Business plans send OTP and transactional SMS. Promotional SMS is available on Enterprise, with approved templates.

Infrastructure

  • TLS on every connection: the website, the dashboard and the API
  • HSTS so browsers refuse to connect over plain HTTP
  • Dashboard requests go server to server; tokens never reach the browser
  • Error responses never include stack traces or internal details
  • Separate rate limits for sign-in, the dashboard and the API

Reliability

  • Idempotency-Key on every POST: replays for 24 h never send twice
  • Leases on routing and webhooks, so no two workers act on one message
  • Smart routing with automatic retries; a message that finally fails is credited back
  • Webhooks retried 8 times with backoff, never twice per status
  • Background jobs safe to run across several servers
See the delivery pipeline

Responsible disclosure

Found a security issue? Tell us first.

Email security@lacspace.com with what you found, how to reproduce it and what you think the impact is. We read every report and will keep you posted as we fix it.

  • Test only against your own account and workspace
  • Don’t access, change or delete other people’s data
  • Don’t send SMS to numbers you don’t own, and don’t run denial-of-service tests
  • Give us reasonable time to fix the issue before sharing it publicly
Email the security team

Privacy

We process phone numbers and message content only to deliver your messages and run the service. Your workspace’s data is visible only to your workspace. Our privacy policy explains what we collect, why, and your rights.

A note on certifications

SMSRay does not currently hold third-party security certifications. This page describes the controls we have built. If your review needs more detail, write to security@lacspace.com.

Send with confidence

Hashed keys, signed webhooks and approved templates, on every plan from day one.

Already a customer? Log in