Security Practices
Data Protection
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Every tenant's data is isolated by row-level security (RLS) at the database layer, and access tokens are encrypted at rest with AES-256-GCM.
Access Controls
Access to customer data is restricted to authorized personnel who need it to perform their job functions. Application secrets and credentials are never exposed to the browser.
Encryption
Data is encrypted in transit using industry-standard TLS. Meta WhatsApp access tokens are encrypted at rest (AES-256-GCM) and proactively refreshed before expiry.
Application Security
Responses carry an enforced Content-Security-Policy, HSTS, and anti-framing headers. Inbound WhatsApp webhooks are verified with Meta's HMAC-SHA256 signature and rejected if invalid (fail-closed).
Availability
We monitor our platform availability and respond promptly to any service issues.
Specific security certifications (SOC 2, ISO 27001, HIPAA) are not claimed unless Legal/Security confirms an attestation genuinely exists.