Security, privacy, and compliance are not features.
They are how we built the platform.
Every customer interaction processed through the Wemacx platform — whether voice, WhatsApp, email, chat, or AI — carries with it a responsibility to protect the data involved. This page documents how Wemacx meets that responsibility: through the architecture of the platform, the policies that govern it, and the controls available to every enterprise customer.
We address security, privacy, data governance, compliance, infrastructure, and AI accountability in one place — because enterprise procurement teams, CISOs, legal teams, and compliance officers should not have to piece together these answers from scattered documentation.
Secure by Design
Security integrated at every layer of the platform — not added as a post-deployment consideration.
Privacy First
Customer data is owned by the customer. Wemacx does not use conversation data to train public AI models.
Enterprise Ready
Architecture, controls, and documentation that meet the requirements of regulated industries globally.
Compliance Driven
Aligned with ISO 27001, SOC 2 Type II, GDPR, HIPAA, ISO 9001, and industry-specific regulatory requirements.
Security integrated into every layer of the platform — not applied at the perimeter.
The Wemacx security architecture addresses protection at each layer of the platform independently — from the infrastructure that hosts the service, through the APIs that connect it to enterprise systems, to the AI services that process customer conversations, and the storage layers that retain interaction data.
Each layer carries its own security controls, its own audit trail, and its own access boundary. A breach at one layer does not cascade to others. This is not a perimeter security model — it is a defence-in-depth architecture where every component operates under the assumption that others may be compromised.
Security improvements are continuous. The platform undergoes regular internal security reviews, and findings are tracked through a formal remediation process. Customers are not required to take action to receive security improvements — they are applied at the platform level and take effect across all deployments.
Authentication & Authorisation
Multi-factor authentication, session management, and role-based access controls enforced at the platform layer. Authentication events are logged with full context for audit and investigation.
API Security
All APIs are authenticated, rate-limited, and monitored. Webhook endpoints are validated for authenticity. API keys are scoped to specific permissions and can be revoked independently.
AI Service Security
AI processing operates within the customer's defined infrastructure boundary. Conversation data processed by AI services is not retained beyond the session without explicit customer configuration.
Customer Data & Conversation Storage
Customer interaction data is stored in isolated environments. Data is encrypted at rest. Access to stored recordings and transcripts is governed by role-based permissions and logged.
Continuous Monitoring & Logging
Infrastructure and application events are monitored continuously. Security-relevant events generate alerts. All administrative actions are captured in an immutable audit log.
Built for regulated industries — and the compliance frameworks they operate within.
Wemacx is designed to operate within the compliance requirements of banking, financial services, healthcare, insurance, government, and telecommunications — industries where the consequences of non-compliance are operational, legal, and reputational.
Quality Management System
Wemacx operates under a documented quality management framework aligned with ISO 9001 standards — covering service delivery, process control, customer feedback, and continuous improvement. Our quality management processes ensure consistent, measurable service standards across the platform.
Information Security Management
Our information security management practices are aligned with the ISO 27001 framework — covering risk assessment, security controls, incident management, and ongoing review. ISO 27001 alignment ensures that information security is managed systematically rather than reactively.
Security, Availability & Confidentiality
Wemacx maintains SOC 2 Type II compliance, independently evaluated across the Trust Services Criteria for Security, Availability, and Confidentiality. SOC 2 Type II reports are available to enterprise customers under NDA upon request.
European Data Protection Regulation
Data processing under the Wemacx platform is conducted in accordance with GDPR requirements — including lawful basis for processing, data subject rights, data minimisation, purpose limitation, and retention governance. Wemacx acts as a data processor under customer instruction.
Healthcare Data Protection
For healthcare customers processing Protected Health Information, Wemacx supports HIPAA-compliant deployment configurations. Business Associate Agreement execution is available for qualifying healthcare deployments.
TRAI, RBI, IRDAI, DPDPA 2023
For customers operating in regulated Indian industries — banking, insurance, telecommunications, and financial services — Wemacx supports deployment configurations and data handling practices aligned with sector-specific regulatory requirements including TRAI, RBI guidelines, IRDAI directives, and the Digital Personal Data Protection Act 2023.
A note on compliance documentation
Compliance certifications and audit reports are available to enterprise customers under a Non-Disclosure Agreement. To request compliance documentation, security architecture overviews, or to initiate a formal security review, please contact our enterprise security team through the link at the bottom of this page.
Data in transit and data at rest — both protected, with no customer configuration required.
All web traffic between customers, agents, and the Wemacx platform is encrypted using TLS 1.3 — the current industry standard for transport security. This applies to browser sessions, API calls, webhook deliveries, and the agent desktop application. Unencrypted communication with the platform is not permitted.
VoIP signalling uses TLS 1.3 for SIP trunking via Session Border Controllers. WebRTC sessions are secured with DTLS for key exchange and SRTP for voice media encryption — ensuring that voice data in transit is protected end-to-end, from the browser or device through to the platform infrastructure.
Customer data stored on the Wemacx platform — including voice recordings, conversation transcripts, metadata, and customer records — is encrypted at rest. Encryption keys are managed within a dedicated key management infrastructure, isolated from the data they protect.
Encryption coverage across the platform
Browser & Web Traffic
TLS 1.3 — all customer-facing and agent-facing browser sessions
API Connections
TLS 1.3 — all inbound and outbound API communication
Webhook Delivery
TLS 1.3 — all webhook payloads delivered to customer endpoints
Agent Desktop
TLS 1.3 — all agent desktop application traffic
VoIP Signalling (SIP)
TLS 1.3 via SBC — SIP trunking signalling and session negotiation
WebRTC Voice Media
DTLS key exchange + SRTP media encryption for browser-based voice
Omnichannel Traffic
TLS 1.3 — WhatsApp, SMS, email, and social channel message delivery
Data at Rest
Encryption at rest — voice recordings, transcripts, metadata, customer records
Key Management
Dedicated key management infrastructure, isolated from encrypted data
Security controls built into every layer of the cloud architecture — not applied after the fact.
Cloud-hosted enterprise software carries unique security obligations. Wemacx addresses each of them through architectural decisions rather than configuration options — so that security properties are consistent regardless of how the platform is deployed or how many tenants share the infrastructure.
Tenant Data Isolation
In shared infrastructure deployments, logical tenant separation is enforced using dedicated database schemas per organisation. This architectural boundary prevents cross-tenant data access at the application layer — no tenant can query, read, or affect the data of any other tenant, regardless of how the underlying infrastructure is shared.
Data Residency & Sovereignty
Permanent customer data can be pinned to a specific geographic region — India, the European Union, the United States, or other supported regions. This enables organisations to meet data localisation requirements under GDPR, India's Digital Personal Data Protection Act 2023, and equivalent regulations in other jurisdictions without requiring on-premises deployment.
PII & PCI Redaction
Automatic redaction of personally identifiable and payment card information from call transcripts, chat logs, and interaction records. Credit card numbers, Aadhaar identifiers, Social Security Numbers, and configurable sensitive data patterns are detected and masked before storage — preventing sensitive data from persisting in interaction records unnecessarily.
Omnichannel Channel Security
WhatsApp Business API, SMS, email, and social media integrations are secured using TLS 1.3 for all message delivery and webhook traffic. Web chat deployments support domain whitelisting — restricting the chat widget to authorised domains only — preventing unauthorised embedding or data capture from third-party sites.
Session Management
Agent and administrator sessions use short-lived authentication tokens with configurable expiry. Automatic logout is enforced after configurable periods of inactivity. Concurrent session controls prevent the same agent credentials from being used simultaneously across multiple devices — reducing the risk of credential sharing.
QA & Recording Access Controls
Supervisors and quality analysts can only access interaction recordings and evaluations within their configured organisational scope. A supervisor assigned to one team cannot retrieve recordings from another team's queue. All recording access and export activity is tracked in the audit log — providing a complete chain of custody for sensitive interaction content.
Incident Response
Wemacx maintains a defined incident response process covering detection, escalation, containment, and recovery. Customer notification SLAs are defined for security incidents that affect customer data. Breach disclosure procedures are documented in accordance with applicable regulatory requirements — including GDPR 72-hour notification obligations and DPDP Act requirements for Indian operations.
WebRTC & SIP Security
SIP trunking is secured through Session Border Controllers that enforce authentication, rate limiting, and topology hiding at the network edge. WebRTC voice sessions use DTLS for cryptographic key exchange and SRTP for media encryption — providing end-to-end protection of voice data from the browser or device through to the platform.
DLP & Sensitive Data Governance
Data Loss Prevention controls are applied across interaction storage and export paths. Configurable sensitivity rules identify and handle financial data, health information, government identifiers, and other regulated data categories — ensuring that sensitive content is retained, masked, or deleted in accordance with the organisation's defined data governance policies.
Your customers' data belongs to your organisation. We process it on your behalf — nothing more.
Privacy at Wemacx is a design constraint, not a policy commitment. The boundaries of what we do with customer data are built into how the platform processes it — not into a terms of service page that could change.
Customer Data Ownership
The data your customers share through the Wemacx platform belongs to your organisation. Wemacx processes it under your instruction as a data processor. You determine what is collected, how long it is retained, and when it is deleted. This is not a policy position — it is the operational model.
No Public AI Training
Wemacx does not use customer conversation data — voice recordings, transcripts, chat messages, or any other interaction content — to train, fine-tune, or improve publicly available AI models. Customer conversations are processed to serve the customer in that interaction, and for no other purpose.
Privacy by Design
Data collection within the Wemacx platform is limited to what is necessary to deliver the service requested. The platform does not collect additional data for analytics, product improvement, or third-party purposes without explicit customer authorisation. Purpose limitation is enforced architecturally.
Data Minimisation
Where a business function can be performed with less data, the platform is designed to use less data. Default configurations reflect the minimum necessary data collection to operate the platform. Customers who require additional data collection for their own purposes can configure those settings explicitly.
Secure AI Processing
AI capabilities within the Wemacx platform — including conversation AI, voice intelligence, quality evaluation, and analytics — process customer data within the customer's defined infrastructure boundary. AI processing does not route data through shared multi-tenant inference services unless explicitly configured.
Responsible AI Governance
AI decisions that affect customers — routing, escalation, scoring — are subject to human oversight controls. Customers can review AI decision histories, adjust AI behaviour within their configuration, and override AI outputs. Wemacx does not deploy autonomous AI decision-making that operates outside customer-defined parameters.
Defined retention periods — with full customer control.
By default, customer interaction data is retained for 90 days from the date of the interaction. After 90 days, interaction records are automatically and permanently deleted from the platform. This default applies to voice recordings, chat transcripts, AI-generated transcripts, and all associated conversation metadata.
Default 90-day retention covers
Extended and configurable retention options
Your data, in the region your regulatory obligations require.
By default, permanent customer data — including contact lists, call records, voice recordings, transcripts, and customer metadata — is stored securely in Mumbai, India. For organisations with data residency requirements, regulatory obligations, or latency considerations, regional hosting is available.
Available deployment regions
Why regional hosting matters
Cloud-agnostic architecture — deployed where your security and infrastructure policies require.
Wemacx is designed to operate across the major enterprise cloud platforms — AWS, Google Cloud Platform, and Oracle Cloud Infrastructure — as well as private cloud environments. This agnosticism is deliberate: enterprise infrastructure strategies vary, and the Wemacx platform should accommodate that variation rather than require customers to adapt to it.
Deployment model selection is made in consultation with the customer during the procurement and implementation process. Each model carries different implications for data residency, operational responsibility, and cost structure. Our implementation team works with customer IT and security teams to select the configuration that best meets their requirements.
Compatible cloud infrastructure
Multi-Tenant SaaS
The standard cloud deployment model — shared infrastructure with strict logical data isolation between customers. Each customer's data is isolated at the application and storage layer. This model offers the fastest deployment and continuous platform updates.
Dedicated Cloud
A dedicated instance of the Wemacx platform provisioned exclusively for a single customer, hosted within a shared cloud infrastructure. Resources are not shared with other customers. Suitable for organisations requiring resource isolation without full private cloud commitment.
Single Tenant
Complete isolation at the infrastructure level — dedicated compute, storage, and networking provisioned exclusively for a single customer. Offers the strongest isolation boundary available within a cloud hosting model.
Hybrid Cloud
A deployment configuration that combines elements of cloud-hosted and customer-managed infrastructure — typically used when specific data types or processing requirements must remain within a customer-controlled environment while other platform components operate in the cloud.
Private Cloud
Deployment within a customer-managed or customer-specified private cloud environment. Suitable for customers with established private cloud infrastructure who require the Wemacx platform to operate within that boundary.
Granular access control across every function of the platform.
Access within the Wemacx platform is governed by a role-based access control system that operates at multiple levels of the organisational hierarchy. Permissions are granted to roles, roles are assigned to users, and the scope of each permission is bounded by the organisational level at which it is granted.
Access control levels
Permissions available for granular control
Integration permissions are managed independently — an administrator can grant API access without granting reporting access, and recording access without granting administrative rights.
Every administrative action, every access event — logged and auditable.
Operational transparency means that every significant event within the platform is recorded, timestamped, and accessible for review. Customers can investigate historical access events, configuration changes, and data access without raising a support request.
Audit Logs
Immutable record of all platform events — configuration changes, data access, user actions, and system events — with timestamps and actor identification.
User Activity Tracking
What each user accessed, when, and from where — searchable and filterable for security investigations and compliance reviews.
Login History
Authentication events — successful logins, failed attempts, MFA challenges, and session terminations — retained for the configured audit period.
Permission Tracking
History of permission assignments, role changes, and access grants — providing a clear record of how access evolved over time.
API Activity Monitoring
All API calls logged with endpoint, caller identity, response code, and timestamp — supporting both security monitoring and integration troubleshooting.
Platform infrastructure designed for the availability requirements of enterprise operations.
Customer engagement operations run continuously — often across time zones and outside standard business hours. The Wemacx platform infrastructure is designed with this in mind: high-availability architecture, automated failover, regular backup, and disaster recovery capability are operational requirements, not options.
AI that operates within boundaries your organisation defines — with humans able to review, override, and correct.
AI capabilities within Wemacx are not autonomous systems. They operate within customer-configured parameters, their outputs are subject to human review, and their behaviour can be adjusted, restricted, or overridden by authorised administrators. Enterprise AI governance is a design requirement, not an afterthought.
A summary of security, compliance, privacy, and infrastructure capabilities.
| Capability | Category | Status |
|---|---|---|
| ISO 9001 | Compliance | Available |
| ISO 27001 | Compliance | Available |
| SOC 2 Type II | Compliance | Available |
| GDPR | Privacy | Available |
| HIPAA | Compliance | Available |
| TLS Encryption in Transit | Security | Available |
| Encryption at Rest | Security | Available |
| Role-Based Access Control | Access Control | Available |
| Customer Data Ownership | Privacy | Available |
| No Public AI Training | Privacy | Available |
| 90-Day Default Retention | Data Governance | Available |
| Configurable Retention | Data Governance | Available |
| Long-Term Archival | Data Governance | Available |
| Compliance Retention | Data Governance | Available |
| Multi-Region Hosting | Data Residency | Available |
| Mumbai (Default Region) | Data Residency | Available |
| AWS Compatible | Deployment | Available |
| Google Cloud Compatible | Deployment | Available |
| Oracle Cloud Compatible | Deployment | Available |
| Private Cloud Compatible | Deployment | Available |
| Dedicated / Single Tenant | Deployment | Available |
| Audit Logging | Transparency | Available |
| API Security | Security | Available |
| MFA Support | Access Control | Available |
| Granular Permissions | Access Control | Available |
| Human AI Oversight | AI Governance | Available |
| TLS 1.3 Encryption | Encryption | Available |
| SRTP Voice Media Encryption | Encryption | Available |
| DTLS WebRTC Security | Encryption | Available |
| Tenant Data Isolation | Cloud Security | Available |
| PII / PCI Redaction | Cloud Security | Available |
| Session Management Controls | Access Control | Available |
| Omnichannel Channel Security | Cloud Security | Available |
| QA Recording Access Controls | Access Control | Available |
| Incident Response Plan | Governance | Available |
| DPDP Act 2023 Alignment | Compliance | Available |
Security and compliance documentation available to enterprise customers on request.
Enterprise procurement, security review, and vendor due diligence processes require documentation that goes beyond what a public webpage can appropriately contain. Wemacx maintains a library of enterprise security and compliance documentation available to qualified customers and prospects under a Non-Disclosure Agreement.
To initiate a documentation request or formal security review, contact our enterprise security team. Requests are handled directly by our security and compliance team — not routed through a general support queue.
Security Architecture Overview
Technical documentation of the Wemacx security architecture — component-level, with trust boundaries and data flows.
Compliance Documentation
SOC 2 Type II reports, ISO alignment documentation, and compliance framework mapping — available under NDA.
Data Processing Information
Documentation of data processing activities, sub-processors, data flows, and GDPR data processing records.
Privacy Documentation
Privacy impact assessment documentation, data subject rights procedures, and privacy framework alignment.
Security Questionnaires
Completion of standard security questionnaires — including SIG, VSA, CAIQ, and custom enterprise security assessments.
Business Associate Agreement
BAA execution available for qualifying HIPAA-covered healthcare deployments.
Security and compliance questions deserve direct answers.
Our enterprise security team is available to provide them.
Whether you are in active procurement, conducting a vendor security assessment, or preparing for a compliance review, our team can provide the documentation, answers, and engagement your process requires. Contact us directly — or schedule a security review session with our enterprise security and compliance team.
Compliance documentation is available under NDA to qualified enterprise customers and prospects. Security questionnaires are completed directly by our enterprise security team.