Engagetic
SECURITY

Your customers' conversations, protected

Engagetic handles the conversations your business runs on. Here's how we keep them private, available, and yours.

PRINCIPLES

Security principles we design against

Encrypted everywhere

All data is encrypted in transit with TLS 1.2 or higher, and encrypted at rest using AES-256.

Least-privilege access

Access to production systems is restricted to the engineers who need it, protected by multi-factor authentication, and logged.

Tenant isolation

Every customer's conversations, contacts, and campaigns are logically separated. One customer's data is never visible to another.

Your data stays yours

We don't sell data, and we don't use one customer's conversations to train models for anyone else. Export or delete your data at any time.

INFRASTRUCTURE

Built on infrastructure we don't have to apologise for

Engagetic runs on AWS. Infrastructure is managed as code, changes are reviewed before they ship, and production access is audited.

HOSTING
AWS
BACKUPS
Automated daily backups with tested restores
MONITORING
Availability and error monitoring with alerting
CHANGE CONTROL
Peer-reviewed code, versioned infrastructure
WHATSAPP PLATFORM

What WhatsApp handles, and what we do

WhatsApp messages are delivered through the WhatsApp Business Platform operated by Meta. Messages are encrypted in transit between WhatsApp and Engagetic, and Meta processes message content as part of delivery under its own terms. Once a conversation reaches Engagetic, it is stored and protected under the controls described on this page.

Engagetic is an independent platform and is not affiliated with or endorsed by Meta. We hold Business Solution Provider access under Meta's terms, and we enforce WhatsApp's messaging policies across our customers to keep the channel healthy for everyone on it.

Consent is a shared responsibility. Engagetic records opt-in and opt-out per contact, and requires every customer to message only people who have agreed to hear from them.

AI

Controlled, reviewable AI

No cross-customer training

Your conversations are never used to train models serving other customers.

Vetted providers

AI processing runs on established model providers under enterprise terms that prohibit training on our data.

Human escalation

Escalation rules put a person in the loop for sensitive conversations, and every AI message is logged and reviewable.

COMPLIANCE

Where we stand today

PRIVACY
We process personal data under our Privacy Policy, and offer a data processing agreement to customers who need one.
DATA RIGHTS
Access, export, correction, and deletion are supported for customers and their end users. See our Data Deletion page.
SOC 2
Not yet certified. We are building towards independent certification and will publish progress here.
GDPR
We support GDPR obligations for customers operating in the EU, including DPAs and standard contractual clauses for transfers.

Found a problem? Tell us.

If you believe you've found a security vulnerability in Engagetic, email support@engagetic.com with enough detail to reproduce it. We aim to acknowledge reports within two business days and will keep you updated while we investigate. Please don't publicly disclose an issue before we've had a chance to fix it, and don't access or modify other customers' data while testing.

Email support@engagetic.com