Security

You are trusting us with your customers’ conversations. Here is, plainly, how we protect them. We describe the controls we actually run — no certifications we don’t yet hold.

1. Encryption in transit

All traffic to and from our services runs over TLS (HTTPS). Messages between your customers, WhatsApp, and our platform travel over encrypted connections end to end of our control.

2. Phone numbers are hashed, not exposed

In our audit and analytics records, customer phone numbers and message content are hashed with HMAC-SHA-256 using a secret key before storage — so operational logs cannot be read back to a real person or number.

3. A layered safety pipeline on every message

Each conversation runs through guardrails before and after the AI responds:

  • Pre-response checks — refusal patterns and escalation triggers are evaluated before the AI is called.
  • Confidence scoring — every reply carries a confidence signal; low-confidence answers are withheld or escalated rather than guessed.
  • Output guards — domain guardrails and disclaimer rules run on the generated reply before it reaches your customer.

4. Human escalation, not blind automation

When the AI is unsure, or a message matches an escalation rule, the conversation is handed to your team from the dashboard. The machine knows when to stop.

5. Audit logging

Key actions are recorded to a structured audit trail (with PII hashed as above), so behaviour can be reviewed and accounted for after the fact.

6. Access control & tenant isolation

  • Each business’s data is isolated to its own tenant; one business can never read another’s customers or conversations.
  • Dashboard access is protected by phone-based OTP verification and short-lived signed session tokens.

7. Payments

Payments are processed by established, PCI-DSS-compliant payment gateways. We do not store your card details on our servers.

8. Consent & your rights

Customers can opt out of promotional messages at any time by replying STOP, and can exercise their data rights as set out in our Privacy Policy, including deletion on request.

9. Reporting a vulnerability

Found a security issue? We want to hear from you. Email [email protected] with “SECURITY” in the subject line. Please give us a reasonable window to investigate and fix before public disclosure.