Trust Center
We treat security and privacy as a product. Below are our policies, certifications, sub-processors, and the controls that protect data flowing through WhatsApp.
Platform controls
Encryption
AES-256-GCM at rest. TLS 1.3 in transit. Argon2id for passwords.
Isolation
Postgres RLS policies plus tenant-scoped indexes. Tenant isolation tested in CI.
Audit
Immutable audit log per tenant. WORM storage. 12-month retention minimum.
WhatsApp & Meta trust
Official Cloud API
All WhatsApp traffic runs through Meta’s Cloud API — we never use unofficial or reverse-engineered clients.
Opt-in enforced
Tenants must evidence recipient consent per the Acceptable Use Policy; opt-outs are recorded and auto-excluded.
Deletion on request
End customers who never signed up for ChatDaddy can still request deletion of their data — see below.
Compliance posture
| Framework | Status | ETA |
|---|---|---|
| SOC 2 Type I | In progress | Q3 2026 |
| SOC 2 Type II | Planned | Q1 2027 |
| GDPR | Compliant | — |
| CCPA / CPRA | Compliant | — |
| ISO 27001 | Planned | Q4 2027 |
| HIPAA | Add-on tier | Q2 2027 |