Aller au contenu

Sécurité & mentions légales

Sécurité

Dernière mise à jour:

Modèle destiné à la revue par un conseil juridique — ce document n'a pas encore été validé et peut ne pas refléter les conditions définitives. En cas de divergence, la version anglaise prévaut.

This page summarizes the technical and organizational measures Blaze Technologies Inc ("Xelp") maintains to protect customer data. It mirrors Annex 2 of our DPA; for security questionnaires or to report a vulnerability, contact privacy@xelp.io.

Encryption

  • In transit: TLS encryption for all connections — browser to platform, platform to channel APIs, and webhooks.
  • At rest: encryption at rest is provided through our infrastructure providers (see Sub-processors).
  • Secrets: connected-channel credentials and customer AI provider keys are stored encrypted and are never written to logs.

Access control

  • Role-based access control in the product: page-level permissions via Roles & Access, so each agent sees only the modules their role grants.
  • Tenant isolation: logical separation of each customer's data within the Service; every query is business-scoped.
  • Xelp personnel: least-privilege access, multi-factor authentication for administrative access, and confidentiality obligations for all personnel.
  • Audit trail: an append-only, in-product log of administrative actions taken inside a workspace (Settings → Business → Audit Trail).

Hosting & operations

  • Hosted with the infrastructure providers listed on the Sub-processors page — Cloudflare (frontend, CDN, WAF/DDoS protection, edge security) and Railway (backend hosting and data storage).
  • Security logging, monitoring, and alerting for anomalous activity.
  • Regular backups and recovery procedures through our infrastructure providers.
  • Vulnerability management: secure development practices, dependency and vulnerability scanning. Report issues to privacy@xelp.io.

Data residency options

Businesses can configure their own media storage bucket (Cloudflare R2 or S3-compatible) for chat media, keeping media objects in storage they control (Settings → Data → Media).

Compliance posture

Xelp operates on the WhatsApp Business Platform and Meta developer platforms and implements Meta's data-deletion and deauthorize callbacks (see Data Deletion Instructions). Our controls are aligned with the measures described in DPA Annex 2. We do not claim certifications we do not hold; any formal certifications will be announced on this page.

Incident response

Documented incident-response procedures. We notify affected customers of a Security Incident involving their personal data without undue delay, and in any event within 72 hours of becoming aware, as described in the DPA (Section 4.5), and we notify authorities where required by applicable law.

Data lifecycle

In-app tools for data access, export, and deletion; permanent deletion upon account termination with a 7-day cancellable grace period — see Data Deletion Instructions.