Enterprise Trust Center

Security, privacy, and compliance are not features.
They are how we built the platform.

Every customer interaction processed through the Wemacx platform — whether voice, WhatsApp, email, chat, or AI — carries with it a responsibility to protect the data involved. This page documents how Wemacx meets that responsibility: through the architecture of the platform, the policies that govern it, and the controls available to every enterprise customer.

We address security, privacy, data governance, compliance, infrastructure, and AI accountability in one place — because enterprise procurement teams, CISOs, legal teams, and compliance officers should not have to piece together these answers from scattered documentation.

Secure by Design

Security integrated at every layer of the platform — not added as a post-deployment consideration.

Privacy First

Customer data is owned by the customer. Wemacx does not use conversation data to train public AI models.

Enterprise Ready

Architecture, controls, and documentation that meet the requirements of regulated industries globally.

Compliance Driven

Aligned with ISO 27001, SOC 2 Type II, GDPR, HIPAA, ISO 9001, and industry-specific regulatory requirements.

Security integrated into every layer of the platform — not applied at the perimeter.

The Wemacx security architecture addresses protection at each layer of the platform independently — from the infrastructure that hosts the service, through the APIs that connect it to enterprise systems, to the AI services that process customer conversations, and the storage layers that retain interaction data.

Each layer carries its own security controls, its own audit trail, and its own access boundary. A breach at one layer does not cascade to others. This is not a perimeter security model — it is a defence-in-depth architecture where every component operates under the assumption that others may be compromised.

Security improvements are continuous. The platform undergoes regular internal security reviews, and findings are tracked through a formal remediation process. Customers are not required to take action to receive security improvements — they are applied at the platform level and take effect across all deployments.

Authentication & Authorisation

Multi-factor authentication, session management, and role-based access controls enforced at the platform layer. Authentication events are logged with full context for audit and investigation.

API Security

All APIs are authenticated, rate-limited, and monitored. Webhook endpoints are validated for authenticity. API keys are scoped to specific permissions and can be revoked independently.

AI Service Security

AI processing operates within the customer's defined infrastructure boundary. Conversation data processed by AI services is not retained beyond the session without explicit customer configuration.

Customer Data & Conversation Storage

Customer interaction data is stored in isolated environments. Data is encrypted at rest. Access to stored recordings and transcripts is governed by role-based permissions and logged.

Continuous Monitoring & Logging

Infrastructure and application events are monitored continuously. Security-relevant events generate alerts. All administrative actions are captured in an immutable audit log.

Built for regulated industries — and the compliance frameworks they operate within.

Wemacx is designed to operate within the compliance requirements of banking, financial services, healthcare, insurance, government, and telecommunications — industries where the consequences of non-compliance are operational, legal, and reputational.

ISO 9001

Quality Management System

Wemacx operates under a documented quality management framework aligned with ISO 9001 standards — covering service delivery, process control, customer feedback, and continuous improvement. Our quality management processes ensure consistent, measurable service standards across the platform.

ISO 27001

Information Security Management

Our information security management practices are aligned with the ISO 27001 framework — covering risk assessment, security controls, incident management, and ongoing review. ISO 27001 alignment ensures that information security is managed systematically rather than reactively.

SOC 2 Type II

Security, Availability & Confidentiality

Wemacx maintains SOC 2 Type II compliance, independently evaluated across the Trust Services Criteria for Security, Availability, and Confidentiality. SOC 2 Type II reports are available to enterprise customers under NDA upon request.

GDPR

European Data Protection Regulation

Data processing under the Wemacx platform is conducted in accordance with GDPR requirements — including lawful basis for processing, data subject rights, data minimisation, purpose limitation, and retention governance. Wemacx acts as a data processor under customer instruction.

HIPAA

Healthcare Data Protection

For healthcare customers processing Protected Health Information, Wemacx supports HIPAA-compliant deployment configurations. Business Associate Agreement execution is available for qualifying healthcare deployments.

Industry Regulatory Alignment

TRAI, RBI, IRDAI, DPDPA 2023

For customers operating in regulated Indian industries — banking, insurance, telecommunications, and financial services — Wemacx supports deployment configurations and data handling practices aligned with sector-specific regulatory requirements including TRAI, RBI guidelines, IRDAI directives, and the Digital Personal Data Protection Act 2023.

A note on compliance documentation

Compliance certifications and audit reports are available to enterprise customers under a Non-Disclosure Agreement. To request compliance documentation, security architecture overviews, or to initiate a formal security review, please contact our enterprise security team through the link at the bottom of this page.

Data in transit and data at rest — both protected, with no customer configuration required.

All web traffic between customers, agents, and the Wemacx platform is encrypted using TLS 1.3 — the current industry standard for transport security. This applies to browser sessions, API calls, webhook deliveries, and the agent desktop application. Unencrypted communication with the platform is not permitted.

VoIP signalling uses TLS 1.3 for SIP trunking via Session Border Controllers. WebRTC sessions are secured with DTLS for key exchange and SRTP for voice media encryption — ensuring that voice data in transit is protected end-to-end, from the browser or device through to the platform infrastructure.

Customer data stored on the Wemacx platform — including voice recordings, conversation transcripts, metadata, and customer records — is encrypted at rest. Encryption keys are managed within a dedicated key management infrastructure, isolated from the data they protect.

Encryption coverage across the platform

Browser & Web Traffic

TLS 1.3 — all customer-facing and agent-facing browser sessions

API Connections

TLS 1.3 — all inbound and outbound API communication

Webhook Delivery

TLS 1.3 — all webhook payloads delivered to customer endpoints

Agent Desktop

TLS 1.3 — all agent desktop application traffic

VoIP Signalling (SIP)

TLS 1.3 via SBC — SIP trunking signalling and session negotiation

WebRTC Voice Media

DTLS key exchange + SRTP media encryption for browser-based voice

Omnichannel Traffic

TLS 1.3 — WhatsApp, SMS, email, and social channel message delivery

Data at Rest

Encryption at rest — voice recordings, transcripts, metadata, customer records

Key Management

Dedicated key management infrastructure, isolated from encrypted data

Security controls built into every layer of the cloud architecture — not applied after the fact.

Cloud-hosted enterprise software carries unique security obligations. Wemacx addresses each of them through architectural decisions rather than configuration options — so that security properties are consistent regardless of how the platform is deployed or how many tenants share the infrastructure.

Tenant Data Isolation

In shared infrastructure deployments, logical tenant separation is enforced using dedicated database schemas per organisation. This architectural boundary prevents cross-tenant data access at the application layer — no tenant can query, read, or affect the data of any other tenant, regardless of how the underlying infrastructure is shared.

Data Residency & Sovereignty

Permanent customer data can be pinned to a specific geographic region — India, the European Union, the United States, or other supported regions. This enables organisations to meet data localisation requirements under GDPR, India's Digital Personal Data Protection Act 2023, and equivalent regulations in other jurisdictions without requiring on-premises deployment.

PII & PCI Redaction

Automatic redaction of personally identifiable and payment card information from call transcripts, chat logs, and interaction records. Credit card numbers, Aadhaar identifiers, Social Security Numbers, and configurable sensitive data patterns are detected and masked before storage — preventing sensitive data from persisting in interaction records unnecessarily.

Omnichannel Channel Security

WhatsApp Business API, SMS, email, and social media integrations are secured using TLS 1.3 for all message delivery and webhook traffic. Web chat deployments support domain whitelisting — restricting the chat widget to authorised domains only — preventing unauthorised embedding or data capture from third-party sites.

Session Management

Agent and administrator sessions use short-lived authentication tokens with configurable expiry. Automatic logout is enforced after configurable periods of inactivity. Concurrent session controls prevent the same agent credentials from being used simultaneously across multiple devices — reducing the risk of credential sharing.

QA & Recording Access Controls

Supervisors and quality analysts can only access interaction recordings and evaluations within their configured organisational scope. A supervisor assigned to one team cannot retrieve recordings from another team's queue. All recording access and export activity is tracked in the audit log — providing a complete chain of custody for sensitive interaction content.

Incident Response

Wemacx maintains a defined incident response process covering detection, escalation, containment, and recovery. Customer notification SLAs are defined for security incidents that affect customer data. Breach disclosure procedures are documented in accordance with applicable regulatory requirements — including GDPR 72-hour notification obligations and DPDP Act requirements for Indian operations.

WebRTC & SIP Security

SIP trunking is secured through Session Border Controllers that enforce authentication, rate limiting, and topology hiding at the network edge. WebRTC voice sessions use DTLS for cryptographic key exchange and SRTP for media encryption — providing end-to-end protection of voice data from the browser or device through to the platform.

DLP & Sensitive Data Governance

Data Loss Prevention controls are applied across interaction storage and export paths. Configurable sensitivity rules identify and handle financial data, health information, government identifiers, and other regulated data categories — ensuring that sensitive content is retained, masked, or deleted in accordance with the organisation's defined data governance policies.

Your customers' data belongs to your organisation. We process it on your behalf — nothing more.

Privacy at Wemacx is a design constraint, not a policy commitment. The boundaries of what we do with customer data are built into how the platform processes it — not into a terms of service page that could change.

Customer Data Ownership

The data your customers share through the Wemacx platform belongs to your organisation. Wemacx processes it under your instruction as a data processor. You determine what is collected, how long it is retained, and when it is deleted. This is not a policy position — it is the operational model.

No Public AI Training

Wemacx does not use customer conversation data — voice recordings, transcripts, chat messages, or any other interaction content — to train, fine-tune, or improve publicly available AI models. Customer conversations are processed to serve the customer in that interaction, and for no other purpose.

Privacy by Design

Data collection within the Wemacx platform is limited to what is necessary to deliver the service requested. The platform does not collect additional data for analytics, product improvement, or third-party purposes without explicit customer authorisation. Purpose limitation is enforced architecturally.

Data Minimisation

Where a business function can be performed with less data, the platform is designed to use less data. Default configurations reflect the minimum necessary data collection to operate the platform. Customers who require additional data collection for their own purposes can configure those settings explicitly.

Secure AI Processing

AI capabilities within the Wemacx platform — including conversation AI, voice intelligence, quality evaluation, and analytics — process customer data within the customer's defined infrastructure boundary. AI processing does not route data through shared multi-tenant inference services unless explicitly configured.

Responsible AI Governance

AI decisions that affect customers — routing, escalation, scoring — are subject to human oversight controls. Customers can review AI decision histories, adjust AI behaviour within their configuration, and override AI outputs. Wemacx does not deploy autonomous AI decision-making that operates outside customer-defined parameters.

Defined retention periods — with full customer control.

By default, customer interaction data is retained for 90 days from the date of the interaction. After 90 days, interaction records are automatically and permanently deleted from the platform. This default applies to voice recordings, chat transcripts, AI-generated transcripts, and all associated conversation metadata.

Default 90-day retention covers

Voice Recordings
Chat & Messaging Transcripts
AI-Generated Transcripts
Conversation Metadata

Extended and configurable retention options

Extended retention periods — beyond the 90-day default
Customer-configured retention — set by policy, queue, or interaction type
Long-term archival — for audit, compliance, or historical reference
Compliance retention — aligned to regulatory minimum retention requirements

Your data, in the region your regulatory obligations require.

By default, permanent customer data — including contact lists, call records, voice recordings, transcripts, and customer metadata — is stored securely in Mumbai, India. For organisations with data residency requirements, regulatory obligations, or latency considerations, regional hosting is available.

Available deployment regions

India (Default) · Mumbai
Germany · Frankfurt
France · Paris
United Kingdom · London
Canada · Toronto
Singapore · Singapore
Australia · Sydney
UAE · Dubai

Why regional hosting matters

Data residency — data physically located within a defined national boundary
Data sovereignty — data subject to the laws of a specific jurisdiction
Regulatory compliance — meeting sector-specific data localisation requirements
Latency — geographic proximity between customer and platform infrastructure

Cloud-agnostic architecture — deployed where your security and infrastructure policies require.

Wemacx is designed to operate across the major enterprise cloud platforms — AWS, Google Cloud Platform, and Oracle Cloud Infrastructure — as well as private cloud environments. This agnosticism is deliberate: enterprise infrastructure strategies vary, and the Wemacx platform should accommodate that variation rather than require customers to adapt to it.

Deployment model selection is made in consultation with the customer during the procurement and implementation process. Each model carries different implications for data residency, operational responsibility, and cost structure. Our implementation team works with customer IT and security teams to select the configuration that best meets their requirements.

Compatible cloud infrastructure

Amazon Web Services (AWS)
Google Cloud Platform (GCP)
Oracle Cloud Infrastructure
Private Cloud

Multi-Tenant SaaS

The standard cloud deployment model — shared infrastructure with strict logical data isolation between customers. Each customer's data is isolated at the application and storage layer. This model offers the fastest deployment and continuous platform updates.

Dedicated Cloud

A dedicated instance of the Wemacx platform provisioned exclusively for a single customer, hosted within a shared cloud infrastructure. Resources are not shared with other customers. Suitable for organisations requiring resource isolation without full private cloud commitment.

Single Tenant

Complete isolation at the infrastructure level — dedicated compute, storage, and networking provisioned exclusively for a single customer. Offers the strongest isolation boundary available within a cloud hosting model.

Hybrid Cloud

A deployment configuration that combines elements of cloud-hosted and customer-managed infrastructure — typically used when specific data types or processing requirements must remain within a customer-controlled environment while other platform components operate in the cloud.

Private Cloud

Deployment within a customer-managed or customer-specified private cloud environment. Suitable for customers with established private cloud infrastructure who require the Wemacx platform to operate within that boundary.

Granular access control across every function of the platform.

Access within the Wemacx platform is governed by a role-based access control system that operates at multiple levels of the organisational hierarchy. Permissions are granted to roles, roles are assigned to users, and the scope of each permission is bounded by the organisational level at which it is granted.

Access control levels

Company Enterprise-wide access — platform administration and global configuration
Office Location or site-specific access boundaries
Department Functional group access — service, sales, collections, support
Team Team-level access — supervisors see their team, not others
User Individual user permissions — configurable at the person level

Permissions available for granular control

Recordings Reports AI Features Dashboards Integrations APIs Administration QA Management Workforce Management

Integration permissions are managed independently — an administrator can grant API access without granting reporting access, and recording access without granting administrative rights.

Every administrative action, every access event — logged and auditable.

Operational transparency means that every significant event within the platform is recorded, timestamped, and accessible for review. Customers can investigate historical access events, configuration changes, and data access without raising a support request.

Audit Logs

Immutable record of all platform events — configuration changes, data access, user actions, and system events — with timestamps and actor identification.

User Activity Tracking

What each user accessed, when, and from where — searchable and filterable for security investigations and compliance reviews.

Login History

Authentication events — successful logins, failed attempts, MFA challenges, and session terminations — retained for the configured audit period.

Permission Tracking

History of permission assignments, role changes, and access grants — providing a clear record of how access evolved over time.

API Activity Monitoring

All API calls logged with endpoint, caller identity, response code, and timestamp — supporting both security monitoring and integration troubleshooting.

Platform infrastructure designed for the availability requirements of enterprise operations.

Customer engagement operations run continuously — often across time zones and outside standard business hours. The Wemacx platform infrastructure is designed with this in mind: high-availability architecture, automated failover, regular backup, and disaster recovery capability are operational requirements, not options.

High-availability architecture — redundancy at the compute, network, and storage layers
Continuous monitoring — automated detection of infrastructure and application anomalies
Regular backup and tested restoration — backup processes verified through scheduled restoration testing
Disaster recovery planning — documented RTO and RPO commitments available to enterprise customers
Scalable cloud infrastructure — capacity automatically scales with customer interaction volumes
Fault tolerance — designed to continue operating through individual component failures

AI that operates within boundaries your organisation defines — with humans able to review, override, and correct.

AI capabilities within Wemacx are not autonomous systems. They operate within customer-configured parameters, their outputs are subject to human review, and their behaviour can be adjusted, restricted, or overridden by authorised administrators. Enterprise AI governance is a design requirement, not an afterthought.

Human oversight — all AI outputs subject to human review and override
Customer-controlled AI — AI behaviour configured and restricted by the customer
Secure AI processing — conversation data processed within customer infrastructure boundary
Controlled permissions — AI feature access managed through the RBAC system
No public AI training — customer conversations not used for model improvement
Enterprise AI governance — documented AI usage policies available on request

A summary of security, compliance, privacy, and infrastructure capabilities.

Capability Category Status
ISO 9001 Compliance Available
ISO 27001 Compliance Available
SOC 2 Type II Compliance Available
GDPR Privacy Available
HIPAA Compliance Available
TLS Encryption in Transit Security Available
Encryption at Rest Security Available
Role-Based Access Control Access Control Available
Customer Data Ownership Privacy Available
No Public AI Training Privacy Available
90-Day Default Retention Data Governance Available
Configurable Retention Data Governance Available
Long-Term Archival Data Governance Available
Compliance Retention Data Governance Available
Multi-Region Hosting Data Residency Available
Mumbai (Default Region) Data Residency Available
AWS Compatible Deployment Available
Google Cloud Compatible Deployment Available
Oracle Cloud Compatible Deployment Available
Private Cloud Compatible Deployment Available
Dedicated / Single Tenant Deployment Available
Audit Logging Transparency Available
API Security Security Available
MFA Support Access Control Available
Granular Permissions Access Control Available
Human AI Oversight AI Governance Available
TLS 1.3 Encryption Encryption Available
SRTP Voice Media Encryption Encryption Available
DTLS WebRTC Security Encryption Available
Tenant Data Isolation Cloud Security Available
PII / PCI Redaction Cloud Security Available
Session Management Controls Access Control Available
Omnichannel Channel Security Cloud Security Available
QA Recording Access Controls Access Control Available
Incident Response Plan Governance Available
DPDP Act 2023 Alignment Compliance Available

Security and compliance documentation available to enterprise customers on request.

Enterprise procurement, security review, and vendor due diligence processes require documentation that goes beyond what a public webpage can appropriately contain. Wemacx maintains a library of enterprise security and compliance documentation available to qualified customers and prospects under a Non-Disclosure Agreement.

To initiate a documentation request or formal security review, contact our enterprise security team. Requests are handled directly by our security and compliance team — not routed through a general support queue.

Security Architecture Overview

Technical documentation of the Wemacx security architecture — component-level, with trust boundaries and data flows.

Compliance Documentation

SOC 2 Type II reports, ISO alignment documentation, and compliance framework mapping — available under NDA.

Data Processing Information

Documentation of data processing activities, sub-processors, data flows, and GDPR data processing records.

Privacy Documentation

Privacy impact assessment documentation, data subject rights procedures, and privacy framework alignment.

Security Questionnaires

Completion of standard security questionnaires — including SIG, VSA, CAIQ, and custom enterprise security assessments.

Business Associate Agreement

BAA execution available for qualifying HIPAA-covered healthcare deployments.

Security and compliance questions deserve direct answers.
Our enterprise security team is available to provide them.

Whether you are in active procurement, conducting a vendor security assessment, or preparing for a compliance review, our team can provide the documentation, answers, and engagement your process requires. Contact us directly — or schedule a security review session with our enterprise security and compliance team.

Compliance documentation is available under NDA to qualified enterprise customers and prospects. Security questionnaires are completed directly by our enterprise security team.