Security
How Weflux keeps your data and your customers' data safe.
Last updated · 1 May 2026 · Effective for all Weflux customers globally.
1. Security programme
Weflux runs a documented information security programme covering encryption, access control, data segregation, retention and deletion. The controls described on this page are the ones we operate today, and we would rather list those precisely than claim a certification we do not yet hold.
If your procurement process needs a security review, a completed questionnaire or a signed DPA, write to security@weflux.in and we will work through it directly.
2. Infrastructure
All traffic between your browser, our services and Meta is encrypted in transit using TLS with modern cipher suites. Customer Data is encrypted at rest, and sensitive credentials - WhatsApp access tokens, webhook verify tokens and SMTP passwords - are additionally encrypted at the application layer with AES-256-GCM before storage, so they are never written in plaintext. Account passwords are hashed with bcrypt and are never stored or logged in plaintext.
Production is segregated from staging and development, and administrative access to production is restricted to named engineers. Ask us for specifics on hosting location and data residency and we will answer honestly for your contract, rather than publish infrastructure detail that mainly helps an attacker.
3. Access controls
Internal access follows the principle of least privilege, and access is revoked promptly on role change or departure. Production data access is restricted to the engineers who need it for a specific task.
For customers
Inside your workspace you can set role-based permissions, so that seeing a conversation and being able to broadcast to your whole contact list are separate rights. If you need SAML single sign-on, tell us: it is not available today and we will not pretend otherwise.
4. Data handling
Customer Data is encrypted at rest, segregated per workspace, and never used for product development or model training. Backups are encrypted and retained for 30 days. Deletion follows our Data Deletion Policy.
5. Vulnerability management
Dependencies are monitored for known vulnerabilities and patched, and code changes are reviewed before release. If your procurement requires evidence of a third-party penetration test, talk to us about scope and timing before you commit rather than after.
Responsible disclosure
Found a security issue? Email security@weflux.in with details. We respond within 48 hours and reward valid reports based on severity. Please don't disclose publicly until we've shipped a fix.
6. Incident response
In the event of a confirmed security incident affecting Customer Data, we notify affected customers without undue delay and no later than 72 hours after confirmation, consistent with Indian and EU data-protection expectations.
7. Standards & reports
- DPDP Act 2023 (India) - aligned
- Signed Data Processing Agreement available on request
- GDPR-aligned controls for EU customers
- SOC 2 and ISO 27001: not currently held. We will say so here if that changes.
8. Contact
For security questions or to report a vulnerability, write to security@weflux.in. PGP key on request.