Security
Last updated: August 9, 2026
Cavyro holds two sensitive things: your CRM and a live connection to your Telegram account. Here is how we treat both.
Infrastructure
- Production runs at Hetzner in Falkenstein, Germany (EU), servers and object storage alike.
- All traffic is encrypted in transit with TLS: browser to app, app to Telegram, service to service.
- Workspaces are isolated from each other; every request is checked against your workspace membership and role.
- Access to production is limited to the people who operate it.
Your Cavyro account
- Passwords are stored as bcrypt hashes. We never see the plain text.
- Two-factor authentication is built in and free on every plan. Standard TOTP, so it works with the authenticator app you already use, whether that's Google Authenticator, Apple Passwords or 1Password.
- Turning it on gives you single-use recovery codes, so a lost phone doesn't mean a lost account.
- Every active session is listed in Settings. Sign out any device, or all of them at once.
Your Telegram connection
- The mirror connects over Telegram's own MTProto protocol, like one of your devices. There is no password sharing; you authorize the session yourself.
- You can see and revoke Cavyro's session from Telegram's settings at any time, independently of us.
- You choose which chats the mirror sees. Excluded chats are never stored.
- Campaign sending is paced with randomized intervals and daily caps, and pauses automatically when Telegram signals trouble.
Payments
Checkout and billing run through Paddle as merchant of record. Card numbers never reach our servers.
Deletion
Deleting a workspace deletes its data immediately, mirrored conversations included. Residual copies in encrypted backups expire on a rolling basis shortly after.
Reporting a vulnerability
Found something? Email support@cavyro.com with the details. We read every report, respond quickly, and will credit you if you want us to. Please give us a reasonable window to fix the issue before disclosing it publicly.