SECURITY AND CONTROL
Your data has one address. Yours.
Smack runs on a server you choose, in a country you choose. Every message, file, recording and log stays in storage your company controls.
What you own.
Your conversations are company records.
Messages, threads and polls live in your own database, on your server.
Your files and recordings are in your storage.
On the server itself, or with a storage provider and region you pick.
No one at Wolfiz can read your data.
We have no access to your install unless you invite us, for example during installation, and you can remove that access when we’re done.
Leaving is simple.
It is your database and your storage. There is nothing to get back from us.
Where everything lives.
Two places hold everything: your database and your storage. Both are yours.
| What | Where it lives |
|---|---|
| Messages, threads, reactions and the audit log | Your database, on your server |
| Files, recordings, whiteboards and transfers | Your storage: on the server, or a provider and region you choose |
| Calls and meetings | Your server. They never pass through Wolfiz. |
| Email notifications | Your own email server |
| Desktop app updates | Your server |
Who can see what.
From a client who gets one file to your CEO, each person sees only what their part needs.
Only those files, until the link expires, behind a password if you set one.
Only that meeting, and only after being let in or entering the passcode.
Public channels, the channels their roles open, and their own conversations.
Also manages that channel’s members and who may post in it.
Manages people, roles and settings. Every action is written to the audit log.
Everything an admin can do, and can never be locked out.
Read receipts show “Seen by” only to the person who sent the message.
Bar length shows how broad each person’s view is, not an exact measure.
Controls you hold.
Each one is a switch your admins set, not a promise we make.
- Decide where people can sign in from: office-only, with named exceptions.
- Sign people in with your own employee IDs, with no email needed.
- Set what each role can do. Channels open and close with the role.
- Limit who can post in announcement channels.
- Set how long messages stay editable: 5 minutes by default, the same for everyone.
- Lock meetings, use waiting rooms and passcodes, and remove anyone.
- Recordings are always announced with a visible REC sign. Nobody is recorded silently.
- Put passwords and expiry dates on file transfers, and revoke any transfer.
- Choose whether message text appears in email and browser notifications.
When someone leaves.
Leavers worry owners more than ciphers do. Here is exactly what happens.
- From active to deactivated
Deactivate.
One click ends their sessions, cancels the meetings they host and stops their transfer links.
- HISTORY KEPT
History stays.
Their messages stay where they were, as company records.
- DELETED
Delete for good, if you must.
Only the CEO can do it, by typing the person’s name to confirm. An entry stays in the audit log.
A record of every admin action.
Sign-ins and failed sign-ins, role and permission changes, settings, meetings, transfers and deletions are written down with who, what and when. The log can’t be edited from the app, and it lives in your own database, where your auditors can read it.
| When | Who | What |
|---|---|---|
| 08 Oct 09:12 | Priya Raman | Role assigned: Hana Kobayashi → Team Lead |
| 08 Oct 09:14 | Priya Raman | IP policy updated: Remote engineering |
| 08 Oct 11:02 | — | Sign-in failed: msilva (wrong password) |
| 08 Oct 11:03 | — | Sign-in blocked: msilva (outside office network) |
| 08 Oct 16:40 | Liam O’Connor | Transfer revoked: Apollo field kit |
| 08 Oct 17:05 | Priya Raman | Account deactivated: Daniel Mensah |
Backups are two jobs.
Because Smack runs on your server, your backups follow your company’s policy. Smack keeps everything in two places, so a backup is two well-known jobs.
Back up the database.
Messages, people, settings and the audit log. A nightly database backup covers it.
Back up the storage.
Files, recordings and transfers. Turn on versioning at your storage provider, or copy the bucket.
Our installation service sets up daily database backups and storage versioning for you.
COMPLIANCE
Your servers.
Your compliance scope.
Smack holds no certifications of its own today. Because it runs on your infrastructure, it sits inside the controls you already have, whether that is data residency, client confidentiality or internal policy. You choose the country your data lives in.
We fill it in line by line. No badges, no fine print.
- Your country.
- Your auditors.
- Your policies.
What Smack doesn’t do yet.
We’d rather tell you now than in your security review.
Ask about the roadmap- Not yetSingle sign-on (SAML, OIDC) and SCIM provisioning
- Not yetTwo-factor sign-in
- Not yetMobile apps (Smack works in mobile browsers)
- Not yetEnd-to-end encrypted messages
- Not yetRetention schedules, legal hold and eDiscovery export
- Not yetBulk export of all data from inside the app
- Not yetThird-party certifications (Smack runs in your environment, under your certifications)
Found a security problem?
Write to us. We reply within 2 business days, and we’ll tell you what we’re doing about it.
Questions.
Something else? Talk to us →
Is our data encrypted on the way?
Yes. Every app connects to your server over HTTPS.
Is our data encrypted when stored?
Your storage’s own encryption covers files and recordings, and your server’s disk encryption covers the database. You choose both.
Can Wolfiz read our messages?
No. Your install runs on your server, and we have no access unless you give it to us.
Can we run our own penetration test?
Yes. It’s your server.
Do you have SOC 2 or ISO 27001?
No. Smack runs inside your infrastructure, so it falls under your own controls and certifications.
Can we get this as a document for our IT team?
Yes. Ask us and we’ll send a one-page security summary.
NOTHING LEAVES. UNLESS YOU SEND IT.
Bring your security questionnaire; we’ll answer it line by line.
Your server · your database · your storage