SECURITY BY OWNERSHIP
Security & private deployment
Self-hosting means data, keys, and access policy stay under your control. imcore's security rests on real features, not compliance badges.
Security is a system boundary, not a badge
From network and keys to access control and audit, every layer fits into your existing governance.
Data sovereignty
Self-hosted: messages, user data, and keys stay on your own servers / VPC and never pass through a third party.
Transport & auth
WSS / TLS encrypted transport; JWT-authenticated connections; WebSocket Origin allowlist; API rate limiting; SSRF protection on outbound webhooks.
Access control & tamper-evident audit
The admin console provides RBAC. Admin actions enter an HMAC-chained audit log protected by database immutability constraints, with recursive redaction of sensitive fields.
Data lifecycle
Configure message retention by policy version, conversation or group. Archive expired messages to object storage and cold tiers with checksum manifests, then use recoverable deletion.
Data subjects & legal hold
Support complete user-data export with attachment manifests, account erasure/anonymization, and legal holds scoped to users, conversations or groups.
Content safety
Built-in content moderation and sensitive-word filtering.
Deployment & observability
Intranet / offline deployment supported; Prometheus metrics (/metrics) and health checks (/healthz) plug into your monitoring.
Backup & recovery drills
PostgreSQL/MySQL drill tooling verifies restore workflows and emits JSON RPO/RTO evidence. Actual targets require recurring drills in your deployment environment.
Compliance stance
We don't ship pre-baked third-party certification badges. Self-hosting lets you run inside your own compliance boundary — your data, your keys, your audit and access policy.
YOUR INFRASTRUCTURE. YOUR RULES.