Sign-in and API keys
Members sign in with Google — Kisoasms never sees a password. API keys are shown once at creation and stored hashed; rotate them, revoke them, or give them an expiry from the dashboard.
Kisoasms moves SMS between your phones and your systems. Here is exactly how that data is handled — and what stays in your hands.
Members sign in with Google — Kisoasms never sees a password. API keys are shown once at creation and stored hashed; rotate them, revoke them, or give them an expiry from the dashboard.
Organizations have members with roles (owner, admin, developer…). Keys are scoped, invitations are explicit, and nobody sees more than their role allows.
The audit log records what was done and by whom — never message text, keys or secrets. When something changes, the record says who changed it.
AI-assisted mobile-money recognition is off by default and enabled per organization. When on, one-time codes and phone numbers are masked before any text reaches Groq or Google Gemini.
Received SMS text is kept 90 days by default; your organization sets 1 to 3,650 days. Webhook delivery events are kept 30 days. Unsent messages expire from the queue after 24 hours.
Kisoasms runs on Cloudflare (Workers, D1, Durable Objects, Queues). Data processors are Cloudflare, Google for sign-in, and Groq / Google Gemini only where AI recognition is enabled.
Found something? Tell the team directly instead of publishing it — include what you did, what you saw, and how to reproduce it.
Contact the team