Skip to content

SECURITY AND CONTROL

Your data has one address. Yours.

Smack runs on a server you choose, in a country you choose. Every message, file, recording and log stays in storage your company controls.

Your data’s address: your company, your server, your country.

What you own.

  1. Your conversations are company records.

    Messages, threads and polls live in your own database, on your server.

  2. Your files and recordings are in your storage.

    On the server itself, or with a storage provider and region you pick.

  3. No one at Wolfiz can read your data.

    We have no access to your install unless you invite us, for example during installation, and you can remove that access when we’re done.

  4. Leaving is simple.

    It is your database and your storage. There is nothing to get back from us.

Where everything lives.

Two places hold everything: your database and your storage. Both are yours.

Where each kind of data lives
WhatWhere it lives
Messages, threads, reactions and the audit logYour database, on your server
Files, recordings, whiteboards and transfersYour storage: on the server, or a provider and region you choose
Calls and meetingsYour server. They never pass through Wolfiz.
Email notificationsYour own email server
Desktop app updatesYour server

Who can see what.

From a client who gets one file to your CEO, each person sees only what their part needs.

  1. A transfer recipient

    Only those files, until the link expires, behind a password if you set one.

  2. A meeting guest

    Only that meeting, and only after being let in or entering the passcode.

  3. A member

    Public channels, the channels their roles open, and their own conversations.

  4. A channel owner

    Also manages that channel’s members and who may post in it.

  5. An admin

    Manages people, roles and settings. Every action is written to the audit log.

  6. The CEO

    Everything an admin can do, and can never be locked out.

Read receipts show “Seen by” only to the person who sent the message.

Bar length shows how broad each person’s view is, not an exact measure.

Controls you hold.

Each one is a switch your admins set, not a promise we make.

  • Decide where people can sign in from: office-only, with named exceptions.
  • Sign people in with your own employee IDs, with no email needed.
  • Set what each role can do. Channels open and close with the role.
  • Limit who can post in announcement channels.
  • Set how long messages stay editable: 5 minutes by default, the same for everyone.
  • Lock meetings, use waiting rooms and passcodes, and remove anyone.
  • Recordings are always announced with a visible REC sign. Nobody is recorded silently.
  • Put passwords and expiry dates on file transfers, and revoke any transfer.
  • Choose whether message text appears in email and browser notifications.

When someone leaves.

Leavers worry owners more than ciphers do. Here is exactly what happens.

  1. From active to deactivated

    Deactivate.

    One click ends their sessions, cancels the meetings they host and stops their transfer links.

  2. HISTORY KEPT

    History stays.

    Their messages stay where they were, as company records.

  3. DELETED

    Delete for good, if you must.

    Only the CEO can do it, by typing the person’s name to confirm. An entry stays in the audit log.

A record of every admin action.

Sign-ins and failed sign-ins, role and permission changes, settings, meetings, transfers and deletions are written down with who, what and when. The log can’t be edited from the app, and it lives in your own database, where your auditors can read it.

An excerpt from an audit log
WhenWhoWhat
08 Oct 09:12Priya RamanRole assigned: Hana Kobayashi → Team Lead
08 Oct 09:14Priya RamanIP policy updated: Remote engineering
08 Oct 11:02—Sign-in failed: msilva (wrong password)
08 Oct 11:03—Sign-in blocked: msilva (outside office network)
08 Oct 16:40Liam O’ConnorTransfer revoked: Apollo field kit
08 Oct 17:05Priya RamanAccount deactivated: Daniel Mensah

Backups are two jobs.

Because Smack runs on your server, your backups follow your company’s policy. Smack keeps everything in two places, so a backup is two well-known jobs.

  1. Back up the database.

    Messages, people, settings and the audit log. A nightly database backup covers it.

  2. Back up the storage.

    Files, recordings and transfers. Turn on versioning at your storage provider, or copy the bucket.

Our installation service sets up daily database backups and storage versioning for you.

COMPLIANCE

Your servers.
Your compliance scope.

Smack holds no certifications of its own today. Because it runs on your infrastructure, it sits inside the controls you already have, whether that is data residency, client confidentiality or internal policy. You choose the country your data lives in.

We fill it in line by line. No badges, no fine print.

  • Your country.
  • Your auditors.
  • Your policies.

What Smack doesn’t do yet.

We’d rather tell you now than in your security review.

Ask about the roadmap
  • Not yetSingle sign-on (SAML, OIDC) and SCIM provisioning
  • Not yetTwo-factor sign-in
  • Not yetMobile apps (Smack works in mobile browsers)
  • Not yetEnd-to-end encrypted messages
  • Not yetRetention schedules, legal hold and eDiscovery export
  • Not yetBulk export of all data from inside the app
  • Not yetThird-party certifications (Smack runs in your environment, under your certifications)

Found a security problem?

Write to us. We reply within 2 business days, and we’ll tell you what we’re doing about it.

security@wolfiz.com

Questions.

Something else? Talk to us →

Is our data encrypted on the way?

Yes. Every app connects to your server over HTTPS.

Is our data encrypted when stored?

Your storage’s own encryption covers files and recordings, and your server’s disk encryption covers the database. You choose both.

Can Wolfiz read our messages?

No. Your install runs on your server, and we have no access unless you give it to us.

Can we run our own penetration test?

Yes. It’s your server.

Do you have SOC 2 or ISO 27001?

No. Smack runs inside your infrastructure, so it falls under your own controls and certifications.

Can we get this as a document for our IT team?

Yes. Ask us and we’ll send a one-page security summary.

NOTHING LEAVES. UNLESS YOU SEND IT.

Bring your security questionnaire; we’ll answer it line by line.

Your server · your database · your storage