Trust

Security

How AksharWAP protects your workspace, your contacts and your WhatsApp conversations — and how to reach us if you find a problem.

Updated 11 August 2026

Encrypted in transit

TLS on every connection to the application, the API and Meta’s Cloud API. No plaintext hop anywhere in the path.

Least-privilege access

Custom roles gate every module, and API tokens carry only the scopes you grant them.

Everything is logged

An audit log records who changed what, so an account owner can reconstruct any change after the fact.

Official platform only

Messaging runs through Meta’s WhatsApp Cloud API. No unofficial libraries, no automation of the consumer app.

Infrastructure

  • • The application, database and background workers run on hardened cloud infrastructure with restricted network access — the database is not reachable from the public internet.
  • • Traffic is served over HTTPS with modern TLS. Requests arriving on HTTP are redirected, and security headers are set at the edge.
  • • Data at rest sits on encrypted storage, and backups are encrypted with the same protection as the primary data.
  • • Backups are taken on a regular schedule and restores are tested, so a recovery is a procedure rather than an experiment.
  • • Environments are separated: production data is never copied into development or test systems.

Application security

  • • Passwords are stored only as salted one-way hashes. Nobody at AksharWAP can read your password.
  • • Sessions use signed, HTTP-only cookies with a bounded lifetime, and sign-out invalidates the session server-side.
  • • Every workspace is isolated: requests are scoped to the tenant they belong to, so one customer’s contacts and conversations are not reachable from another’s session or token.
  • • Roles and permissions are enforced on the server for every request, not just hidden in the interface.
  • • REST API tokens are scoped per resource family — campaigns, contacts, templates, messages, analytics, users, settings, webhooks, WhatsApp accounts, broadcast, chatbot — and can be revoked at any time.
  • • Inbound webhooks from Meta are signature-verified before they are processed, and outbound webhooks are delivered only to endpoints you configure.
  • • Input is validated at the API boundary, database access is parameterised, and rate limits protect authentication and bulk endpoints.
  • • Dependencies are kept current and patched when advisories affect them.

Access control

Inside your workspace, you decide who can reach what. Custom roles map to the modules a person actually needs, invitations are per-person, and access can be withdrawn immediately.

On our side, access to production is limited to the engineers who need it to operate the service, granted individually rather than through shared logins, reviewed as roles change, and revoked when someone leaves. Support staff do not browse customer conversations; where a support case genuinely needs access, it is requested, time-bound and logged.

WhatsApp and Meta

AksharWAP is built on Meta’s official WhatsApp Cloud API. We do not use unofficial libraries or automate the consumer WhatsApp app — the practice that gets business numbers banned.

  • • Your WhatsApp Business Account stays yours. We connect to it; we do not take ownership of it.
  • • Access tokens issued for your account are stored encrypted and used only to serve your workspace.
  • • Onboarding through Meta’s embedded signup happens in Meta’s own flow — we never see your Facebook password.
  • • Message content in transit between us and Meta is protected by TLS, and Meta applies its own protections on the WhatsApp network beyond that point.

Payments

Subscription payments and wallet top-ups are handled by Razorpay, a PCI-DSS compliant payment gateway. Card numbers, UPI credentials and bank details are entered on Razorpay’s side and never reach our servers or our database — we store only the plan, the invoice and the payment reference Razorpay returns.

Monitoring and incident response

  • • Application and infrastructure logs are collected centrally, and error rates and availability are monitored continuously.
  • • The audit log gives account owners their own record of administrative changes, independent of ours.
  • • When we detect an incident we contain it first, then investigate, then fix the underlying cause.
  • • If a breach affects your data, we notify affected account owners without undue delay — with what happened, what data was involved, and what we are doing about it — and notify the authorities where the DPDP Act or other applicable law requires it.

What you control

Most account compromises start on the customer side, so a few habits matter more than anything on our list:

  • • Use a strong, unique password for your AksharWAP account, and do not share logins between agents — seats are unlimited, so there is no reason to.
  • • Give each person the narrowest role that lets them do their job, and remove access the day someone leaves.
  • • Issue API tokens per integration with only the scopes it needs, and revoke tokens you no longer use.
  • • Send webhooks to HTTPS endpoints you control, and verify what you receive before acting on it.
  • • Import only contact data you have a lawful basis to hold, and keep special-category data off the platform.

Compliance status

We build to the Digital Personal Data Protection Act, 2023 and to Meta’s WhatsApp Business Platform requirements, and the Privacy Policy sets out how customer and end-customer data is handled, retained and deleted.

We do not currently hold a SOC 2 or ISO 27001 certification, and we would rather say so than imply one. If your procurement process needs a security questionnaire completed, a data-processing agreement signed, or a review call with our engineers, write to us and we will work through it.

Reporting a vulnerability

Found something? Email security@aksharwap.com with enough detail to reproduce it — the endpoint or page, the steps, and what you were able to reach. We acknowledge reports within 3 working days and keep you updated until the issue is closed.

Please give us a reasonable window to fix an issue before disclosing it publicly, test only against accounts you own, and avoid anything that degrades the service or touches other customers’ data — no denial-of-service, no spam, no social engineering of our staff or users. We will not pursue action against researchers who follow these rules. We do not run a paid bounty programme today, but we credit reporters who want the acknowledgement.

Security questions or reports

Vulnerability reports, security questionnaires and DPA requests all go to our security inbox.

security@aksharwap.com