Encryption in transit & at rest
All traffic is protected with modern TLS 1.2+ and data is encrypted at rest with AES-256, so your conversations stay private on the wire and on disk.
Convello handles some of your most sensitive conversations, so we treat security as a first-class product feature. We build on the official Meta and WhatsApp Business Platform APIs, encrypt your data end to end of our systems, and hold ourselves to the platform terms that keep your accounts in good standing.
From encryption to access control to the way we ship code, our practices are designed to keep your customer conversations private and your business protected.
All traffic is protected with modern TLS 1.2+ and data is encrypted at rest with AES-256, so your conversations stay private on the wire and on disk.
Granular role-based access control and single sign-on ensure teammates only reach what they need. Access is reviewed regularly and revoked promptly.
Sensitive actions are recorded in tamper-evident audit logs, giving your admins visibility into who did what and when across the workspace.
Hosted on hardened cloud infrastructure with a 99.9% uptime target, automated encrypted backups and disaster-recovery procedures we test regularly.
Code review, automated dependency scanning, and testing are built into every release, so security is checked continuously rather than bolted on.
We vet every subprocessor for security and privacy, keep an up-to-date list, and hold them to contractual data-protection commitments.
Convello connects to your accounts exclusively through the official Meta Graph API and WhatsApp Business Platform — never scraping, never unofficial workarounds. Data we obtain through Meta's APIs is used solely to provide the service you signed up for.
We use the official Meta Graph API and WhatsApp Business Platform — no unofficial access.
Data from Meta APIs is used solely to provide the service — never sold, never repurposed.
We adhere to the Meta Platform Terms and Developer Policies across everything we build.
Request a full data export or deletion at any time — honored within 30 days.
We collect only what's needed to run your workspace and give you the controls to manage it. Your customer conversations belong to you — we're the processor, not the owner.
Compliance posture. Our program is aligned with SOC 2 principles, with a SOC 2 Type II examination in progress. We're happy to share our current status and roadmap with prospective customers under NDA — just reach out to our team.
Data ownership. You can export your workspace data at any time and request deletion through our data deletion process. When you leave, your data leaves with you.
We welcome reports from security researchers and treat them as a priority. If you believe you've found a security issue in Convello, please email [email protected] with the details and steps to reproduce. Please give us a reasonable window to investigate and remediate before any public disclosure — we'll keep you updated throughout and credit your work if you'd like.
Our team is happy to walk through our controls, share documentation, and answer anything your reviewers need.