Skip to content

Security

How we protect your workspace

whatsappx.si protects accounts with hashed passwords and tokens, encrypts Meta channel credentials at rest, separates every workspace’s data and serves everything over HTTPS.

Updated

Safeguards in the product today

  • Hashed passwords

    Passwords are at least 12 characters and stored only as bcrypt hashes.

  • Hashed tokens

    Session and password-reset tokens are stored only as hashes.

  • Single-use reset links

    Password reset links work once and expire after 1 hour.

  • Rate limits

    Sign-in and email endpoints are rate limited.

  • Encrypted credentials

    Meta channel credentials are encrypted at rest.

  • Role-based access

    Owner, admin and agent roles; each workspace’s data is kept separate.

  • HTTPS everywhere

    All traffic to the website, app and API uses HTTPS.

  • Verified sign-in

    Email verification and Google sign-in are supported.

  • API keys and webhook tokens

    The REST API uses Bearer API keys; webhooks send a shared-token header.

Frequently asked questions

Who can see my team’s conversations?
Only members of your workspace. Each workspace’s data is kept separate, and roles control access: owners and admins manage the workspace, and agents can be limited to the chats assigned to them.
How are WhatsApp Business Platform credentials stored?
Credentials for numbers connected through Meta’s official WhatsApp Business Platform are encrypted at rest before they are stored.

Bring your team into one WhatsApp inbox

Create a workspace, connect a number by QR code or the official API, and invite your teammates.