Security

Anonymous by design, protected by construction

TELN removes the usual account attack surface entirely. There is no email to phish, no phone number to hijack and no password reset flow to abuse.

Model

Six pillars of the TELN security model

Each one is a deliberate trade-off in favour of privacy, with the consequences stated plainly.

No identity collected

No email, phone number, username, name or address is required to create an account. There is nothing to leak because nothing is stored.

Passcode-only authentication

A cryptographically random 12-character passcode is generated for you. Confusing characters are excluded so it can be transcribed reliably.

Hashed credentials

TELN stores a one-way hash of the passcode plus a separate lookup hash. Support and administrators cannot read or restore it.

Session visibility

Every session shows browser family, platform, approximate region and last activity. Revoke a single device or every other device instantly.

Passcode rotation

Rotate your passcode at any time by confirming the current one. The old passcode stops working immediately.

Immutable financial history

Wallet movements are append-only ledger entries with the resulting balance. Entries cannot be edited or deleted, by anyone.

Controls

What runs behind the scenes

Platform controls that apply to every account, with no configuration required.

Brute-force protection

Failed sign-in attempts are counted per account and per client. After repeated failures the account locks temporarily and a security event is recorded.

Session lifetime

Sessions carry a short-lived access token and a rotating refresh token. Revoking a session invalidates its refresh token immediately.

Least-privilege data access

Customer data is never readable by anonymous clients. Every read passes through the server with the session bound to a single account.

Provider boundary

Payment and telecom providers receive only what they need to deliver service. Credentials stay server-side and are never exposed to the browser.

Balance safety

Usage reserves and suspend thresholds prevent a wallet from going negative while delayed provider usage records catch up.

Audit trail

Administrative actions are written to an append-only audit log with the actor, action, target and reason.

The honest trade-off

A passcode that nobody can recover means a lost passcode is permanent. TELN cannot restore access, move wallet credit to a new account or verify who you are, because it holds no information about you.

Store your passcode in a password manager before you fund your wallet.

What TELN can still see

TELN processes what is required to run the service: wallet and ledger records, eSIM usage totals, number rentals and incoming SMS content shown in your inbox. Messages follow the platform retention period.

Read the privacy policy

Create an account without giving anything away

One passcode. One wallet. No personal details.