Trust · Security and compliance

Your customer's conversation is sensitive data. We treat it as such.

Data held in Brazil, encryption in transit and at rest, configurable retention and an audit trail for every action. We don't train models on your content and we don't share your base with third parties.

See the status page
Security posture
Data and backups held in Brazilactive
TLS 1.3 encryption and AES-256 at restactive
MFA required for administrative rolesactive
Immutable audit trail of user and system actionsactive
Penetration test by an independent third partyannual
ISO 27001in progress
99.9%
contractual SLA, with credit to your wallet
TLS 1.3
encryption in transit, AES-256 at rest
Brazil
data, replicas and backups held in Brazil
0
conversations used to train an AI model
Layers

Where the data travels, and what protects each leg.

Security isn't a padlock at the end: it's a decision at every layer, from the moment the request arrives to the day the data is deleted.

01
In transit

All communication with the platform happens over an encrypted channel, with no exception for the test environment.

TLS 1.3 required on the API and in the dashboard
HSTS and a managed certificate
Outbound webhook signed with HMAC-SHA256
SMPP with a dedicated TLS port
02
At rest

Message content, attachments and credentials are stored encrypted, with rotated keys.

AES-256 in the database, queue and object storage
Channel credential encrypted and never shown again
API key kept only as a hash
Encrypted backup with a defined retention
03
In access

Who gets in, with what, and for how long — decided by you, recorded by us.

Roles per user and per team
MFA required for administrative roles
API key with a scope and an environment
Immediate, audited revocation
04
In the lifecycle

Data has a deadline. Configurable retention, recorded deletion and export always available.

Content retention from 30 days to 5 years
Contact deletion recorded in the audit trail
Export by API or dashboard, at any time
Personal data masked in the AI log
LGPD

You are the controller. We are the processor.

Your customers' data is yours. We process it on your behalf and under your instructions, for a purpose limited to what the contract defines — and we return or delete it when the relationship ends.

01Purpose limited to the contractWe process the data only to deliver the contracted service. No secondary use, no enrichment, no reselling of your base.
02The legal basis is your responsibilityYou warrant the contact's consent or legal basis; we provide the opt-out, suppression and record-keeping tools.
03Data subject requestsA request that reaches us is forwarded to you. In the dashboard, exporting and deleting a contact's history is a recorded action.
04Appointed data protection officerA direct channel to our DPO for formal requests, with a response time defined in the contract.
See the privacy policy
Content retention6 months

Platform default. Balances support history against the volume of data stored.

Message content and attachments6 months
Delivery and status metadata24 months
Audit log24 months
Billing records5 years (legal)
Access

Each person sees what they need. Each key does what it declared.

Roles per user, MFA required for whoever administers, API keys with separate scope and environment. Revoking access is immediate and stays recorded.

01Four roles, not a switchOwner, administrator, supervisor and agent — each with the minimum needed for the job.
02MFA where it mattersRequired for whoever manages users, keys or the wallet. Authenticator app, with recovery codes.
03Key with a scope and an environmentEach key declares what it can do and whether it acts in production or test. Shown a single time, kept as a hash.
04Immediate revocationRemoving a user or revoking a key cuts access right away, and the action lands in the audit trail with author and time.
See the API documentation
Permissions by role

Access restricted to conversations in the queues they take part in. It is the most common role and the most limited.

Answer conversations in their queues
See the contact's history and notes
Send an approved template
See conversations in other queues
Fire a bulk campaign
See API keys or the wallet
Availability

An SLA worth money, not an intention.

99.9% monthly availability on the send API. If we miss it, the credit goes into the wallet — without you having to ask. Incidents stay public on the status page, including those of the channel providers.

See the status page
CommitmentTargetWhen we miss it
Send API availabilityMeasured monthly, excluding provider failure and announced maintenance99.9%credit to the wallet, applied without you asking
Support first replyOn-call in Portuguese, dedicated channel on the Corporate plan1 business hautomatic escalation to the technical team
Security incident notificationCommunication with scope, containment and recommendationcontractualset out in the data processing agreement
Status publicationOur incidents and those of the channel providersreal timepublic page, no login
Continuity
Backup and restore tested

A daily encrypted routine, with periodic restore testing — a backup nobody restores is not a backup.

Route redundancy

If a channel provider goes down, traffic is redirected to the alternative route available.

A queue that doesn't drop

A volume spike or a slow provider builds up in the queue; no accepted message is lost.

Announced maintenance

A scheduled window announced in advance and published on the status page.

Artificial intelligence

The AI does not learn from your data.

It is the question we get most, and the answer is straightforward: the documents in your base only serve to retrieve context for your own replies, and no conversation feeds model training — neither ours nor the provider's.

See the AI agent
No conversation trains a model

Neither ours nor the model provider's. The contracts with the providers forbid using customer content for training.

Base used only to retrieve context

Your documents serve for the agent to find the right passage and answer citing the source — and nothing beyond that.

Personal data masked in the log

The record of the interaction preserves traceability without exposing ID numbers, the full phone number or payment data.

Tools with minimum scope

What the agent can read or write on your API is declared by you, tool by tool.

Subprocessors

Who else touches the data, and what for.

We publish who takes part in the processing and what for. A change to the list is announced in advance, as set out in the contract.

SubprocessorPurposeRegion
Cloud providerApplication, database and storage hostingBrazil · São Paulo
Meta PlatformsMessage delivery on WhatsApp and Instagramas defined by Meta
Brazilian carriersSMS and RCS deliveryBrazil
AI model providerAgent inference, with no retention for trainingBrazil / USA
Payments providerWallet top-up by Pix and bank slipBrazil
Frequently asked questions

What the customer's security team asks.

Need the signed documents? Request the full package .

On cloud infrastructure in the São Paulo region, within Brazil. Replicas and backups stay in the country. If your policy requires it, we state in writing the exact regions in use at the time of contracting.

Start today with R$ 50 in test credit.

Sandbox wallet released when you create the account, a WhatsApp test number and guided onboarding. No card, no contract.

Book a demoCreate free accountSales reply within 2 business hours
CCX
Brazilian CPaaS platform. WhatsApp, email, SMS, RCS, push and Instagram in a single integration.
All systems operational
© 2026 CCX Digital Solutions LTDA · CNPJ 24.329.191/0001-06 · BrazilTerms of usePrivacySecurityChangelog