Trust
Security at WAFlow
You are trusting us with your customer conversations. Here is exactly how we protect them, and what remains your responsibility.
Encryption
TLS 1.2+ for all traffic to and from the platform, and encryption at rest for the database, backups, and stored Meta access tokens.
Workspace isolation
Every table enforces row-level security keyed to your workspace, so one customer's query can never return another customer's rows.
Least-privilege access
Role-based access inside the app (owner, admin, agent) and scoped API keys. Internal admin access is limited, logged, and used only for support with a clear reason.
Auditability
Authentication events, permission changes, credential changes, and message-sending activity are logged with timestamps and actor identity.
Secure operations
Secrets stored in a managed secret store and never in source control, automated dependency scanning, signed webhook verification, and reviewed changes before release.
Responsible disclosure
We welcome security reports and respond quickly. We do not pursue legal action against good-faith researchers who follow the policy below.
Details
Application security
- Authentication is handled by a managed identity provider with hashed credentials and email verification.
- Sessions use short-lived access tokens with refresh rotation; sign-out revokes the session.
- All server-side data access runs under the caller's identity, so authorisation is enforced by the database as well as the application.
- Inbound Meta webhooks are validated against an HMAC-SHA256 signature before any event is processed.
- Inputs are schema-validated on the server; output is escaped by default to prevent injection and XSS.
Meta credential handling
- Tokens are obtained only through Meta Embedded Signup, with the permissions you explicitly approve.
- Tokens are stored encrypted, never exposed to the browser, and used only for your workspace's requests.
- You can revoke access instantly from WAFlow or from Meta Business settings.
- WAFlow does not use unofficial WhatsApp clients, device emulation, or scraping.
Infrastructure
- Managed cloud hosting with automated patching and isolated environments for development and production.
- Daily encrypted database backups with point-in-time recovery.
- Monitoring and alerting on error rates, delivery failures, and abnormal API usage.
Your responsibilities
- Use a strong, unique password and enable multi-factor authentication on your email and Meta accounts.
- Invite only teammates who need access and remove them when they leave.
- Keep API keys secret and rotate them if exposed.
- Collect valid opt-in and honour opt-outs — this is the single biggest factor in keeping your number healthy.
Reporting a vulnerability
Email security@wafollow.in with steps to reproduce, the affected URL, and any proof of concept. Please test only against your own workspace, avoid denial-of-service and social engineering, and never access or modify other customers' data. We acknowledge within 3 business days and aim to remediate critical issues within 7 days. We are happy to credit you once a fix ships.
Certifications and status
We do not currently claim SOC 2, ISO 27001, HIPAA, or PCI certification. We build to those control categories and will publish independent attestations only when they are actually completed. For our data-protection posture and sub-processors, see compliance and the privacy policy.
Ready to automate WhatsApp the official way?
Connect your own WhatsApp Business Account in minutes with Meta Embedded Signup.