Data held in Brazil, encryption in transit and at rest, configurable retention and an audit trail for every action. We don't train models on your content and we don't share your base with third parties.
Security isn't a padlock at the end: it's a decision at every layer, from the moment the request arrives to the day the data is deleted.
All communication with the platform happens over an encrypted channel, with no exception for the test environment.
Message content, attachments and credentials are stored encrypted, with rotated keys.
Who gets in, with what, and for how long — decided by you, recorded by us.
Data has a deadline. Configurable retention, recorded deletion and export always available.
Your customers' data is yours. We process it on your behalf and under your instructions, for a purpose limited to what the contract defines — and we return or delete it when the relationship ends.
Platform default. Balances support history against the volume of data stored.
Roles per user, MFA required for whoever administers, API keys with separate scope and environment. Revoking access is immediate and stays recorded.
Access restricted to conversations in the queues they take part in. It is the most common role and the most limited.
99.9% monthly availability on the send API. If we miss it, the credit goes into the wallet — without you having to ask. Incidents stay public on the status page, including those of the channel providers.
See the status page →A daily encrypted routine, with periodic restore testing — a backup nobody restores is not a backup.
If a channel provider goes down, traffic is redirected to the alternative route available.
A volume spike or a slow provider builds up in the queue; no accepted message is lost.
A scheduled window announced in advance and published on the status page.
It is the question we get most, and the answer is straightforward: the documents in your base only serve to retrieve context for your own replies, and no conversation feeds model training — neither ours nor the provider's.
See the AI agent →Neither ours nor the model provider's. The contracts with the providers forbid using customer content for training.
Your documents serve for the agent to find the right passage and answer citing the source — and nothing beyond that.
The record of the interaction preserves traceability without exposing ID numbers, the full phone number or payment data.
What the agent can read or write on your API is declared by you, tool by tool.
We publish who takes part in the processing and what for. A change to the list is announced in advance, as set out in the contract.
Need the signed documents? Request the full package .
Sandbox wallet released when you create the account, a WhatsApp test number and guided onboarding. No card, no contract.
