Esek answers your phone calls and your messages on WhatsApp, Instagram and Messenger. Scams arrive by message too, so here is what is checked today, and what no check can promise.
Links are checked before they open
Links in customer messages, in message buttons and in replies from the AI assistant are checked against Google Web Risk, Google's list of phishing, malware and unwanted software sites.
- A link on that list cannot be opened in the app.
- If the check cannot finish, the link stays locked until it can be checked again. An outage never unlocks a link.
- Only the link itself goes to Google. Not the message around it, not the customer's details, not your business name.
Files are opened on our servers first
Documents sent to you on WhatsApp, Instagram or Messenger are opened on our servers first, and every link inside them is checked the same way. This covers Word, Excel and PowerPoint files, PDFs and text files.
- A file with a dangerous link is blocked on the server. It cannot be opened or downloaded, and there is no way around the block. The conversation stays visible.
- If a file cannot be read in full, for example a password-protected file, you see a warning before opening it.
- If the check cannot finish, the file stays locked and can be checked again.
Scam images and documents from new senders
When someone you have never replied to sends an image or a document, an AI model looks for the signs of a scam:
- posing as Meta, Google, a bank, a courier or a government office
- threats to your account or page, and pressure to act now
- requests to verify, log in, share a code or pay
A likely scam is blocked like a dangerous file. A possible scam shows a warning before you open it.
The model gets the image, or the start of the document's text. It does not get the file name, the caption, the sender's name or number, or the conversation. Files from people you have already replied to are not sent to it.
Blocking a sender
You can block a sender on WhatsApp right from the conversation. Meta allows this only within 24 hours of their last message.
On Instagram and Messenger, block the sender in Meta's own app. Meta gives other apps no way to report a sender, so report it in Meta's app as well.
Your account and data
- Sign in with Google, Apple, email and password, or a code sent to your phone. Sign-in attempts and code requests are rate limited.
- The tokens that connect your WhatsApp, Instagram and Messenger accounts are stored encrypted.
- Passwords and access tokens are left out of the data our servers send to the app.
- The database is backed up every night, and each backup is kept for 30 days.
What these checks cannot do
- No filter catches every scam. A brand-new scam page may not be on Google's list yet, so a link that opens is not proof that it is safe.
- The AI model can miss a scam, and it can flag a harmless file.
- Text messages, voice notes and videos are not checked by the AI model. Links in text messages are still checked.
- These checks only cover what Meta delivers to Esek. Messages opened directly in Meta's own apps do not go through them.
If something looks wrong
- Don't open the link or the file, and never share a code or password.
- Block the sender.
- Report the sender in Meta's own app.
- Email us at info@esek.io.