Sign-in with your phone number
There are no passwords to leak or reuse. You enter your mobile number, we send a one-time code, and the code is valid for a few minutes and a limited number of attempts. Too many wrong codes lock that code out.
Each sign-in becomes a device session you can see and revoke under Settings → Security.
Tokens never touch the page
After sign-in, the session tokens live in httpOnly, SameSite=Lax cookies that JavaScript on the page cannot read. Every API call goes through this site's own server, which adds the token and forwards the request. The access token is short-lived; it is refreshed silently and rotated on every refresh.
State-changing requests must come from this site (an origin check), and responses carrying message data are never stored by the offline cache.
Workspaces see only their own data
A workspace sees its own messages, inbound SMS, API keys, webhooks, templates and contacts — nothing else. New workspaces start as pending until Lacspace activates them.
Pool operations (phones, SIMs, routing, every workspace's traffic) are limited to Lacspace platform staff, and that is enforced on the server, not just hidden in the menu.
API keys and phones
API keys, webhook signing secrets and phone pairing keys are shown exactly once, when they are created or rotated; only a hash or a short prefix is kept for display. Rotating a key cuts the old one off immediately. Webhook secrets can overlap for a grace period so receivers can switch without dropping events.
OTP content
One-time codes are never shown in message logs. The log shows that an OTP was sent, to whom, through which SIM and with what result — not the code.
Reporting a problem
Found something? Write to security@lacspace.com.