Skip to content
Kisoasms

Your messages pass through your phones, not our reading room.

Kisoasms moves SMS between your phones and your systems. Here is exactly how that data is handled — and what stays in your hands.

Security practices

Sign-in and API keys

Members sign in with Google — Kisoasms never sees a password. API keys are shown once at creation and stored hashed; rotate them, revoke them, or give them an expiry from the dashboard.

Roles and teams

Organizations have members with roles (owner, admin, developer…). Keys are scoped, invitations are explicit, and nobody sees more than their role allows.

Audit log

The audit log records what was done and by whom — never message text, keys or secrets. When something changes, the record says who changed it.

AI masking

AI-assisted mobile-money recognition is off by default and enabled per organization. When on, one-time codes and phone numbers are masked before any text reaches Groq or Google Gemini.

Retention you control

Received SMS text is kept 90 days by default; your organization sets 1 to 3,650 days. Webhook delivery events are kept 30 days. Unsent messages expire from the queue after 24 hours.

Hosting

Kisoasms runs on Cloudflare (Workers, D1, Durable Objects, Queues). Data processors are Cloudflare, Google for sign-in, and Groq / Google Gemini only where AI recognition is enabled.

Report a vulnerability

Found something? Tell the team directly instead of publishing it — include what you did, what you saw, and how to reproduce it.

Contact the team