Security
You are trusting us with your customers’ conversations. Here is, plainly, how we protect them. We describe the controls we actually run — no certifications we don’t yet hold.
1. Encryption in transit
All traffic to and from our services runs over TLS (HTTPS). Messages between your customers, WhatsApp, and our platform travel over encrypted connections end to end of our control.
2. Phone numbers are hashed, not exposed
In our audit and analytics records, customer phone numbers and message content are hashed with HMAC-SHA-256 using a secret key before storage — so operational logs cannot be read back to a real person or number.
3. A layered safety pipeline on every message
Each conversation runs through guardrails before and after the AI responds:
- Pre-response checks — refusal patterns and escalation triggers are evaluated before the AI is called.
- Confidence scoring — every reply carries a confidence signal; low-confidence answers are withheld or escalated rather than guessed.
- Output guards — domain guardrails and disclaimer rules run on the generated reply before it reaches your customer.
4. Human escalation, not blind automation
When the AI is unsure, or a message matches an escalation rule, the conversation is handed to your team from the dashboard. The machine knows when to stop.
5. Audit logging
Key actions are recorded to a structured audit trail (with PII hashed as above), so behaviour can be reviewed and accounted for after the fact.
6. Access control & tenant isolation
- Each business’s data is isolated to its own tenant; one business can never read another’s customers or conversations.
- Dashboard access is protected by phone-based OTP verification and short-lived signed session tokens.
7. Payments
Payments are processed by established, PCI-DSS-compliant payment gateways. We do not store your card details on our servers.
8. Consent & your rights
Customers can opt out of promotional messages at any time by replying STOP, and can exercise their data rights as set out in our Privacy Policy, including deletion on request.
9. Reporting a vulnerability
Found a security issue? We want to hear from you. Email [email protected] with “SECURITY” in the subject line. Please give us a reasonable window to investigate and fix before public disclosure.