Security
Anonymous by design, protected by construction
TELN removes the usual account attack surface entirely. There is no email to phish, no phone number to hijack and no password reset flow to abuse.
Model
Six pillars of the TELN security model
Each one is a deliberate trade-off in favour of privacy, with the consequences stated plainly.
No identity collected
No email, phone number, username, name or address is required to create an account. There is nothing to leak because nothing is stored.
Passcode-only authentication
A cryptographically random 12-character passcode is generated for you. Confusing characters are excluded so it can be transcribed reliably.
Hashed credentials
TELN stores a one-way hash of the passcode plus a separate lookup hash. Support and administrators cannot read or restore it.
Session visibility
Every session shows browser family, platform, approximate region and last activity. Revoke a single device or every other device instantly.
Passcode rotation
Rotate your passcode at any time by confirming the current one. The old passcode stops working immediately.
Immutable financial history
Wallet movements are append-only ledger entries with the resulting balance. Entries cannot be edited or deleted, by anyone.
Controls
What runs behind the scenes
Platform controls that apply to every account, with no configuration required.
Brute-force protection
Failed sign-in attempts are counted per account and per client. After repeated failures the account locks temporarily and a security event is recorded.
Session lifetime
Sessions carry a short-lived access token and a rotating refresh token. Revoking a session invalidates its refresh token immediately.
Least-privilege data access
Customer data is never readable by anonymous clients. Every read passes through the server with the session bound to a single account.
Provider boundary
Payment and telecom providers receive only what they need to deliver service. Credentials stay server-side and are never exposed to the browser.
Balance safety
Usage reserves and suspend thresholds prevent a wallet from going negative while delayed provider usage records catch up.
Audit trail
Administrative actions are written to an append-only audit log with the actor, action, target and reason.
The honest trade-off
A passcode that nobody can recover means a lost passcode is permanent. TELN cannot restore access, move wallet credit to a new account or verify who you are, because it holds no information about you.
Store your passcode in a password manager before you fund your wallet.
What TELN can still see
TELN processes what is required to run the service: wallet and ledger records, eSIM usage totals, number rentals and incoming SMS content shown in your inbox. Messages follow the platform retention period.
Create an account without giving anything away
One passcode. One wallet. No personal details.