LetsBot Menu
العربية Get Started

Account Security — Protect Your Business on WhatsApp

Every LetsBot account now supports two-factor authentication, automatic session expiry, sign-in restrictions by IP address, and a tamper-evident security activity log you can export. All included at no extra cost, and off until you choose to turn them on.

IP restrictions do not affect your integrations: order notifications, incoming WhatsApp messages, and store and payment integrations keep working exactly as before. The restriction applies to people signing in, not to systems.

The controls your team runs

Every control is off by default — each workspace turns on what it needs.

Two-factor authentication

Adds a one-time code from an authenticator app on top of the password, so a password alone is no longer enough to get in.

Who it is for: Each user, on their own account — and a workspace owner can require it for the whole team.

In practice: A member of your team hands a password to a phishing page. With 2FA on, that password is worthless: the code lives only on their phone.

Works with any standard authenticator app — Google Authenticator, Microsoft Authenticator, Authy, 1Password and others. No SMS, no extra cost, no vendor lock-in. Setup is a QR scan plus one confirming code, so the account is only protected once a real code has been proven and nobody can lock themselves out by scanning into the wrong app. Eight single-use recovery codes are issued for a lost or replaced phone. And nobody can see or manage another person's 2FA — not a colleague, not the workspace owner, not LetsBot support.

Session timeout policies

Two independent settings per workspace: sign out after a period of inactivity, and a maximum session length regardless of activity.

Who it is for: The workspace owner, applied across the whole team.

In practice: Someone leaves the account open on a shared machine at the end of a shift. The session expires on its own instead of staying open until morning.

It applies even to people who chose "keep me signed in" — that is the point of the control. Particularly useful for shared computers, agency desks, and retail counters.

IP restrictions

A workspace lists the addresses its team signs in from — single addresses or whole ranges, IPv6 included.

Who it is for: The workspace owner, and teams working from an office network or a VPN.

In practice: A password is stolen from outside your network. It is useless, because a sign-in from any address that is not on the list is refused.

There is built-in protection against locking yourself out: the workspace cannot save a list that does not include the address it is being saved from, and the screen shows you that address.

Security activity log

Records every security-relevant event: sign-in, failed sign-in, sign-out, two-factor setup / enable / disable, two-factor verification (success and failure), recovery-code use, session expiry, access denied by an IP restriction, and any change to the workspace's own security settings.

Who it is for: The workspace owner, and anyone who needs a documented answer during a review or a security enquiry.

In practice: An enterprise customer asks for a record of who accessed your account and when. You export the log and send it, and the recipient can verify its integrity themselves.

Each entry carries who, when, from which address, and the outcome. The log is tamper-evident: entries are append-only and cryptographically chained with SHA-256, so any later edit or deletion is detectable and independently verifiable. It exports as CSV or JSONL, and the export carries its own integrity verdict so a recipient can re-check it rather than take it on trust. Available in Arabic, English, Portuguese and Spanish.

Role-based access

Granular per-permission roles per workspace, defining exactly what each member can see and do.

Who it is for: Any team larger than one person.

In practice: A support agent should read conversations without reaching billing or channel settings. You give them a role that contains only what they need.

Roles are already part of the platform; they are listed here to complete the picture.

Does this affect my integrations? No.

IP restrictions do not affect your integrations: order notifications, incoming WhatsApp messages, and store and payment integrations keep working exactly as before. The restriction applies to people signing in, not to systems.

Order notifications Incoming WhatsApp messages Store integrations Payment gateways Webhooks and APIs

How to turn it on

  1. 1

    Turn on 2FA for your own account

    From the user menu at the top of the panel, next to "My profile". Scan the QR code with your authenticator app, enter one code to confirm, then store your recovery codes somewhere safe.

  2. 2

    Set the workspace security policy

    Settings → Security tab. This is where you require 2FA for the team, set session timeouts, and list allowed IP addresses. The tab is available to the workspace owner and super-admin only.

  3. 3

    Review the security activity log

    Before you require 2FA, the screen shows how many members already set it up, so you know the impact before you apply it. After that, every event lands in the log and you can export it whenever you need to.

Already in place

Encryption in transit and at rest

Every connection runs over TLS 1.2 or newer, and sensitive stored credentials are encrypted with AES-256.

Brute-force protection

Applied on every sign-in surface, per account and per source.

Secure API authentication

Secure authentication for integrations, with signed verification of incoming webhooks and per-integration rate limits.

Four languages, full RTL

All of the above ships in Arabic, English, Portuguese and Spanish, with complete right-to-left support.

Frequently asked questions

Is there an extra charge for the security features?
No. Every control on this page is included in every account at no extra cost, and each one is off by default until you choose to turn it on.
Which authenticator apps work?
Any standard authenticator app, including Google Authenticator, Microsoft Authenticator, Authy and 1Password. There is no dependency on SMS and no lock-in to a single provider.
What if I lose my phone?
Eight single-use recovery codes are issued at setup. Keep them somewhere safe and use one to sign in if your phone is lost or replaced, then set two-factor authentication up again on the new device.
Can my team be required to use 2FA?
Yes. A workspace owner can require it for every member from Settings → Security. Before switching it on, the screen shows how many members have already set it up.
Will IP restrictions break my store or WhatsApp integration?
No. Order notifications, incoming WhatsApp messages, and store and payment integrations keep working exactly as before. The restriction applies to people signing in to the panel, not to the systems that connect to your account.
Can I export the activity log for an audit?
Yes, as CSV or JSONL. The export carries its own integrity verdict, so a recipient can re-verify the chain themselves rather than take it on trust.
Can anyone else see my 2FA setup?
No. Nobody can see or manage another person's two-factor setup — not a teammate, not the workspace owner, not LetsBot support.

Turn it on today — at no extra cost

Sign in and start with 2FA on your own account, then set the workspace security policy. If you have an enterprise security questionnaire to fill in, contact us and we will answer it.

Chat with us on WhatsApp