Official onboarding only
Numbers connect through Meta’s embedded signup. No grey-market BSP sits between you and Meta.
WBIZ runs on Meta’s official WhatsApp Cloud API with workspace isolation enforced in the backend, secrets encrypted at rest, HMAC-signed webhooks and an audit log that is on by default rather than sold as an upgrade.
Numbers connect through Meta’s embedded signup. No grey-market BSP sits between you and Meta.
Every data read is filtered by workspace on the server, so tenants cannot see each other’s conversations.
Tokens, credentials and key secrets are encrypted at rest and revealed once at creation.
Outbound webhooks are HMAC-signed, retried with backoff and replayable from the dashboard.
Authentication and secrets
Sessions are short-lived and refreshed, API keys carry per-key scopes, and a key secret is revealed exactly once at creation. Nothing sensitive is stored in plain text, and every key can be rotated or revoked without downtime.
Event integrity
Every outbound event is signed with HMAC-SHA256 so your systems can prove it came from us. Failures retry with backoff, land in a dead letter queue if they exhaust, and can be replayed with one click. Inbound Meta and Razorpay webhooks are verified against the raw request bytes before anything is trusted.
Access control
Roles gate billing, settings and deletion, so a front-line agent can work every conversation without touching anything that costs money or leaks data.
Isolation, logging and data control
Multi-tenancy is the default, not a higher tier. Several WABA numbers can live under one login with per-number filtering.
Activity logs record every change across the product so admins can answer what happened and when.
Consent is tracked per contact with source and history, and privacy requests are supported end to end.
Security FAQ
Send your questionnaire and we will return it completed. For data-protection specifics, see Trust and Compliance.
Messages are delivered by Meta’s Cloud API and stored against your workspace in our database. Access is filtered server-side by workspace, so isolation is enforced by the backend rather than by the interface.
Traffic is encrypted in transit with TLS, and credentials, tokens and API key secrets are encrypted at rest. Key secrets are shown once at creation and can be rotated at any time.
Every inbound Meta and Razorpay webhook is verified with HMAC-SHA256 against the raw request bytes before the payload is parsed or trusted.
Yes. Roles and permissions gate billing, settings, exports and deletion. Agents can work conversations without reaching admin surfaces, and multi-number workspaces can be filtered per number.
Yes, always on. Activity logs record who did what and when across the workspace, and admins can query them to reconstruct an incident.
Yes. Workspace export and account or per-contact deletion are supported for privacy requests, with consent state tracked per contact.
Yes. Send yours through the contact form and we will complete and return it.
Send the questionnaire, the NDA or the architecture questions. You will get written answers, not a brochure.