Trust center
Security at Groupyid
Last reviewed August 24, 2026
Release boundaries
- Carrier SMS/MMS transmission happens only on the selected Android gateway SIM.
- The Stage 1 app has no Internet permission, account SDK, analytics, advertising, remote logging, or developer backup.
- Android backup and screenshots on sensitive app screens are disabled.
- A local PIN protects administrator actions; logs and pilot exports are redacted.
- STOP, deletion tombstones, queue limits, expiry checks, selected-SIM checks, and a final pre-handoff authorization gate fail closed.
- Real sends run only while a visible foreground-service notification is active.
Known boundaries
Ordinary carrier messaging is not end-to-end encrypted by Groupyid. Carriers and recipient devices control transport, retention, sender display, filtering, callbacks, and delivery receipts. Physical device, carrier, dual-SIM, reboot, and flip-phone tests remain necessary for every pilot configuration.
Report a vulnerability
Email support@groupyid.com with the affected app version, a clear description, safe reproduction steps, and impact. Do not include real phone numbers, message content, PINs, carrier credentials, or full databases.
Safe-harbor expectations
Test only systems and devices you own or have explicit permission to test. Avoid privacy violations, social engineering, denial of service, carrier traffic, spam, data destruction, persistence, or accessing another person’s data. Stop and report if personal data appears.
Supported versions
Install current trusted Groupyid releases promptly. Debug builds and modified APKs are for controlled testing and are not production identities.