What Parakh Actually Sees
Parakh is a browser and an on-device scanner. That defines its limits precisely, and the limits are worth stating before the capabilities.
It can see
- Links handed to it, from a message, an email or any app's share sheet
- Pages loaded inside Parakh itself, including whether a page is asking for a password
- QR codes you scan with it
- Apps installed on the phone, their permissions and their known vulnerabilities
- Whether each phone's protections are switched on
It cannot see
- The contents of any message, in any app
- Pages inside another app's built-in browser
- Anything typed outside Parakh
- Contacts, photos, calls or location
- Payments started inside a banking or payment app
What An Administrator Can See
A Work Circle owner or co-admin sees posture, never content. This is the whole list, and it is worth showing your team before they install anything.
| Whether each phone is protected | Yes visible |
|---|---|
| What needs fixing, and how to fix it | Yes visible |
| When a phone last checked in | Yes visible |
| Total links checked and threats stopped | Yes, as a circle total visible |
| Which sites a person visited | Never not collected |
| Which links a specific person opened | Never not collected |
| Anything typed, messaged or photographed | Never not collected |
| Location | Never not collected |
Per-device link volume is deliberately withheld even from administrators. "This phone checked 847 links" reads as surveillance and would contradict the promise the product is sold on.
And What They Can Send
An administrator can post one notice to the circle, and can send a reminder about one thing that needs fixing — "links are skipping Parakh", "your app needs updating". Both arrive as a notification on the phone.
They cannot write the reminder. It is one of nine fixed sentences, each about the recipient's own phone, each with a button that opens the screen that fixes it. Nothing an administrator types reaches anybody's lock screen through Parakh, and a reminder is limited to one every four hours per problem and six a day for the whole circle.
Where It Runs, And What Is Stored
| Service | Delivered from a global edge network, so there is no single server to breach and no regional outage that takes everyone down. |
|---|---|
| Link checking | Links are checked by a one-way hash wherever possible. Cloud checking comes with a plan and is on by default; it can be switched off on any device without disabling protection. |
| On-device data | Link history and page content stay on the phone. They are never uploaded, and our staff cannot read them. |
| Account data | Sign-in identity, devices, licences and protection counters. Nothing about browsing. |
| Backups | The Android app disables OS-level app backup on purpose, so the local database is never copied off the device by the platform. |
| Deletion | Self-service and irreversible from the account page. It removes the account, profile, devices, owned circles, licences and credits. |
Access By Our Support Team
Authorised staff can open a read-only support view of an account to diagnose a problem. That access is:
- Read-only. It writes nothing and changes nothing.
- Logged. Every view records who looked, at what, and when.
- Limited. It shows the same account and device information the customer sees.
- Carved out. It does not include on-device link history or the contents of any page.
This is stated in the privacy policy, not only here.
Standards And Frameworks
Stated plainly, because a vague answer here is worse than a modest one.
| India DPDP Act 2023 | Parakh is built to support a business acting as a data fiduciary: data minimisation, purpose limitation, self-service deletion, and a security-controls record you can produce on request from the Business Console. |
|---|---|
| Security attestation | Available to Work Circle administrators. It is a record of the controls Parakh observes on enrolled phones. It is not a certification or an audit, and it does not claim to be. |
| ISO 27001 / SOC 2 | Not certified today. We will say so plainly rather than imply otherwise. |
| SSO / SAML | Not available today. Sign-in is Google identity. On the roadmap, ungated by any technical blocker. |
| SCIM provisioning | Not available today. Seats are managed by invite code or QR. |
| MDM / UEM integration | Not available, and deliberately so. Parakh is built to be deployable by a business that has no MDM at all. |
| SIEM / SOC feed | Not available today. Administrators can export device posture as CSV, and an audit log of account actions is retained. |
Reporting A Vulnerability
If you believe you have found a security issue, write to security@MagenSec.app. Please include enough detail to reproduce it. We will acknowledge, investigate, and tell you what we found.
Do not test against other people's accounts or data. We will not pursue good-faith research that respects that line.
Who We Are
| Company | XenoCraft Labs Pvt. Ltd., Hyderabad, India |
|---|---|
| Product | Parakh, a MagenSec app |
| Support | support@MagenSec.app |
| Security | security@MagenSec.app |