SECURITY BY OWNERSHIP

Security & private deployment

Self-hosting means data, keys, and access policy stay under your control. imcore's security rests on real features, not compliance badges.

Security is a system boundary, not a badge

From network and keys to access control and audit, every layer fits into your existing governance.

01

Data sovereignty

Self-hosted: messages, user data, and keys stay on your own servers / VPC and never pass through a third party.

02

Transport & auth

WSS / TLS encrypted transport; JWT-authenticated connections; WebSocket Origin allowlist; API rate limiting; SSRF protection on outbound webhooks.

03

Access control & tamper-evident audit

The admin console provides RBAC. Admin actions enter an HMAC-chained audit log protected by database immutability constraints, with recursive redaction of sensitive fields.

04

Data lifecycle

Configure message retention by policy version, conversation or group. Archive expired messages to object storage and cold tiers with checksum manifests, then use recoverable deletion.

05

Data subjects & legal hold

Support complete user-data export with attachment manifests, account erasure/anonymization, and legal holds scoped to users, conversations or groups.

06

Content safety

Built-in content moderation and sensitive-word filtering.

07

Deployment & observability

Intranet / offline deployment supported; Prometheus metrics (/metrics) and health checks (/healthz) plug into your monitoring.

08

Backup & recovery drills

PostgreSQL/MySQL drill tooling verifies restore workflows and emits JSON RPO/RTO evidence. Actual targets require recurring drills in your deployment environment.

09

Compliance stance

We don't ship pre-baked third-party certification badges. Self-hosting lets you run inside your own compliance boundary — your data, your keys, your audit and access policy.

YOUR INFRASTRUCTURE. YOUR RULES.

Keep messaging inside your control plane