WHALEXY Logo Whalexy

Trust center

Security and data protection

Whalexy is designed to help teams operate their customer messaging workspace with controlled access, secure transport, and clear administrative boundaries.

Data in transit

Whalexy is served over HTTPS in production. Connections to Meta services use authenticated API requests. Customers remain responsible for protecting their Meta credentials and limiting access to authorized administrators.

Account and role controls

Workspace access is authenticated, and product permissions can be assigned by role. Teams should use unique accounts, promptly remove former users, and review access whenever responsibilities change.

WhatsApp Cloud API connection

Production messaging requires an eligible WhatsApp Business account and Meta credentials configured during onboarding. Meta policies, template approval, consent requirements, and platform availability apply independently of Whalexy.

Customer responsibilities

Customers should follow data-minimization practices, avoid collecting sensitive credentials in chat, configure retention appropriate to their obligations, and comply with applicable privacy and messaging laws.

Report a security concern

If you believe you found a security issue, email support@whalexy.com with a clear description, affected URL, reproduction steps, and impact. Please do not include customer data, passwords, access tokens, or other secrets.