Trust center
Security and data protection
Whalexy is designed to help teams operate their customer messaging workspace with controlled access, secure transport, and clear administrative boundaries.
Data in transit
Whalexy is served over HTTPS in production. Connections to Meta services use authenticated API requests. Customers remain responsible for protecting their Meta credentials and limiting access to authorized administrators.
Account and role controls
Workspace access is authenticated, and product permissions can be assigned by role. Teams should use unique accounts, promptly remove former users, and review access whenever responsibilities change.
WhatsApp Cloud API connection
Production messaging requires an eligible WhatsApp Business account and Meta credentials configured during onboarding. Meta policies, template approval, consent requirements, and platform availability apply independently of Whalexy.
Customer responsibilities
Customers should follow data-minimization practices, avoid collecting sensitive credentials in chat, configure retention appropriate to their obligations, and comply with applicable privacy and messaging laws.
Report a security concern
If you believe you found a security issue, email support@whalexy.com with a clear description, affected URL, reproduction steps, and impact. Please do not include customer data, passwords, access tokens, or other secrets.
Whalexy