On this page
Our approach: tealsi is designed so Customer tenant data is not ordinarily accessed by tealsi personnel for support purposes without Customer authorization. We maintain technical and administrative controls intended to reduce unauthorized access and protect the Platform.
NO INTERNET-CONNECTED SYSTEM CAN BE GUARANTEED TO BE 100% SECURE. TEALSI USES REASONABLE TECHNICAL AND ADMINISTRATIVE MEASURES, BUT DOES NOT WARRANT THAT THE PLATFORM WILL NEVER EXPERIENCE A SECURITY EVENT, UNAUTHORIZED ACCESS, OUTAGE OR OTHER FAILURE.
1. Scope
This Security & Administrative Access Statement describes tealsi’s general security approach and administrative-access practices. It supplements the Terms of Service, Privacy Policy and Data Processing Addendum.
This Statement is intended as a public overview and does not disclose confidential security architecture, detection thresholds, internal credentials, provider configurations, incident-response playbooks or other information that could reasonably increase security risk.
2. Security Principles
tealsi applies a risk-based approach to Platform security. Security measures may include logical tenant separation, authentication controls, access restrictions, logging, monitoring, rate limiting, progressive lockouts, infrastructure controls, provider safeguards and incident-response procedures.
Security controls may change over time as threats, technologies, providers and Platform architecture evolve.
3. Customer Tenants and Administrative Access
Customer accounts and workspaces (“tenants”) are designed to separate Customer environments and Customer Data from unrelated Customers.
tealsi personnel do not ordinarily access the contents of a Customer tenant for routine support without Customer authorization.
4. Support Access Requires Authorization
When troubleshooting requires access to Customer-specific information or configuration, tealsi may request Customer permission before accessing the applicable tenant or Customer Data.
Customer authorization may be provided through the Platform, support communication, written instruction or another reasonable method accepted by tealsi.
Support access should be limited to the information and duration reasonably necessary to address the Customer’s request.
5. Security, Legal and Infrastructure Exceptions
tealsi may access or process Customer Data without ordinary support authorization where reasonably necessary to:
- investigate or respond to a security incident;
- detect, prevent or investigate fraud, abuse, spam or unauthorized access;
- protect tealsi, other Customers, providers, carriers or infrastructure;
- restore service, recover data or perform essential infrastructure operations;
- preserve evidence;
- comply with applicable law, valid legal process or regulatory obligations; or
- address an emergency or other circumstance where obtaining prior authorization is not reasonably practicable.
6. Least-Privilege Access
tealsi seeks to limit administrative access based on role, operational need and the principle of least privilege. Personnel access should be restricted to those with a legitimate business, support, security, engineering, legal or operational need.
Administrative access practices may include credential controls, role-based permissions, logging and other internal safeguards.
7. Authentication and Account Protection
tealsi may use authentication measures designed to reduce unauthorized account access. These measures may include password controls, session protections, authentication monitoring, rate limiting, account lockouts and additional security requirements based on account or risk conditions.
Where available, Customers are encouraged to use strong unique passwords, multi-factor authentication and appropriately restricted user permissions.
8. Brute-Force and Suspicious Access Protection
tealsi uses automated protections intended to detect and restrict repeated or suspicious authentication attempts, including brute-force behavior.
These protections may include progressive temporary restrictions, longer account or source restrictions, rate limits and permanent blocking where activity reasonably appears abusive, malicious or persistently unauthorized.
Security detail: tealsi intentionally does not publish exact attempt thresholds, lockout windows, detection rules or internal blocking logic because doing so could make those controls easier to evade.
9. Logging and Monitoring
tealsi may maintain authentication, activity, security, audit, API, usage and system logs for legitimate operational purposes, including troubleshooting, fraud prevention, abuse detection, security investigations, billing, compliance and legal defense.
Logs may record information such as timestamps, account activity, authentication events, changes to configurations and other technical events reasonably necessary to operate and protect the Platform.
10. Data Protection and Infrastructure
tealsi uses technical and organizational measures intended to protect Customer Data against unauthorized access, misuse, alteration, loss or disclosure. The specific measures used may vary by system, feature, data type and provider.
Additional security-related processing terms are described in the Data Processing Addendum.
11. Infrastructure and Subprocessors
tealsi relies on third-party infrastructure and technology providers to operate portions of the Platform. These may include hosting, telecommunications, AI, voice, payment, monitoring and other service providers.
Current provider information is maintained in the Subprocessors & Connected Services Notice. Hostinger may be used for VPS and hosting infrastructure in the United States, together with other providers used for specific Platform functions.
12. Customer Security Responsibilities
Customer is responsible for securing Customer’s own users, credentials, devices, browsers, networks, API keys, connected services and internal access practices.
Customer must promptly disable users who should no longer have access and must not share credentials in a manner that creates unreasonable security risk.
tealsi is not responsible for unauthorized activity resulting from Customer’s failure to protect credentials, devices, connected accounts or user permissions, except to the extent responsibility cannot lawfully be excluded.
13. Connected Accounts and Third-Party Integrations
Third-party accounts connected by Customer, including accounts with Meta, Google, TikTok, WhatsApp, Stripe, PayPal and other providers, remain subject to those providers’ own security systems, credentials, permissions and terms.
Customer is responsible for maintaining the security of connected third-party accounts and for revoking access when appropriate.
14. Security Incidents
If tealsi becomes aware of a material security incident affecting Customer Data, tealsi will use commercially reasonable efforts to investigate, contain and address the incident and provide notices required by applicable law or contract.
The timing and content of any notice may depend on the nature of the incident, available information, law-enforcement considerations, provider dependencies and legal requirements.
15. Maintenance and Service Availability
tealsi may perform scheduled maintenance, upgrades, migrations, security updates and other operational work. Where reasonably practicable, tealsi will provide advance notice of material scheduled maintenance expected to significantly affect service availability.
Unexpected technical problems, provider failures or security events may occur without advance notice. tealsi will use commercially reasonable efforts to notify affected Customers as soon as reasonably practicable after becoming aware of a material service disruption.
16. No Guarantee of Absolute Security
tealsi does not guarantee that its security controls will prevent every intrusion, attack, vulnerability, outage, data loss, unauthorized access or malicious act.
Customer acknowledges that internet services, software, telecommunications systems, APIs and third-party infrastructure carry inherent operational and security risks.
17. Abuse, Fraud and Protective Suspension
tealsi may immediately limit, suspend, block or terminate access where tealsi reasonably believes activity presents a security, fraud, abuse, spam, legal, provider or infrastructure risk.
Protective action may occur without prior notice where delay could increase risk to tealsi, Customer Data, other Customers, providers, carriers or the public.
18. Data Access Following Suspension
Where reasonably possible, technically feasible, safe and legally permitted, tealsi may provide limited read-only or export access to Customer Data after a suspension.
tealsi does not guarantee export access where providing access would create a security risk, permit continued prohibited activity, conflict with a legal hold or law-enforcement request, or otherwise be unsafe or unlawful.
19. Data Retention After Cancellation
Following cancellation or termination, Customer Data will generally be deleted or anonymized from active production systems within thirty (30) days, subject to limited retention in backups, logs, billing records, legal holds, fraud records and information tealsi is required or permitted by law to retain.
Customers should export required Customer Data before cancellation or during any available post-cancellation recovery period.
20. Legal Process and Cooperation
tealsi may preserve information and cooperate with valid law-enforcement, regulatory, court, carrier or provider requests where required or permitted by applicable law.
tealsi may also investigate and take action regarding suspected illegal activity, fraud, abuse, threats or violations of the Acceptable Use Policy.
21. Vulnerability Reporting
Security researchers or Customers who believe they have discovered a vulnerability affecting tealsi should report it responsibly to support@tealsi.com and should not exploit, publicly disclose or access Customer Data beyond what is reasonably necessary to demonstrate the issue.
tealsi may establish a dedicated security reporting channel or vulnerability disclosure program in the future.
22. Changes to this Statement
tealsi may update this Security & Administrative Access Statement to reflect changes in Platform architecture, security controls, providers, legal requirements or operational practices.
Material changes may be communicated through the Platform, website, email or another commercially reasonable method.
23. Contact
Questions regarding tealsi security or administrative access practices may be directed to support@tealsi.com.
Restricted access. Layered protection. Practical transparency.
tealsi is designed to limit unnecessary access to Customer environments while maintaining the operational flexibility required to protect the Platform, respond to incidents and comply with law.