How your data is protected.
HQveyra holds the credentials to your business WhatsApp number and every conversation your customers have with you. Here is precisely what we do about that.
Your WhatsApp credentials
Provider tokens are encrypted at rest with AES-256-GCM before they reach the database, under a key held only in the application environment. A database leak on its own does not expose them.
Every message your agent sends goes out through your own provider credentials. There is no shared number and no code path by which one workspace's message could leave from another's.
Green API, our default connection, drives WhatsApp Web rather than Meta's official Business Platform. We use it because it connects your existing number in minutes with no verification process — but you should know what it is. The risk on this route is bulk messaging, so the product makes that hard: your agent answers people who wrote to you first, anything it sends unprompted is capped at fifty a day per workspace and paced at human intervals rather than fired in a burst, and every one of those carries a way to stop them. That keeps a number in good standing. It is not a guarantee, and no tool connecting this way can offer one. Meta's official Cloud API is supported for businesses that would rather use it.
Access to your workspace
Sessions are signed, expire after 30 days, and can be revoked instantly — changing your password invalidates every existing session everywhere.
Two-factor authentication (TOTP) is available on every account.
Only the workspace owner can change billing, alter agency-wide settings, invite teammates, or delete data. Teammates work the inbox without being able to cancel your subscription or wipe your leads.
Team invites are single-use, expire in seven days, are bound to the address they were sent to, and can be revoked at any time.
Your customers' conversations
Every record is scoped to your workspace and filtered by it on every query. Exports are limited to your own data.
Opt-outs are honoured automatically: a customer who replies STOP stops receiving messages, and is excluded from follow-ups and broadcasts.
You can wipe every lead, conversation, listing and appointment from your own settings, without asking us.
Incoming webhooks
Provider webhooks are authenticated before any work is done — a bearer token for Green API, an HMAC signature for Meta and for Paddle. Requests that fail verification are rejected, not logged and processed.
Every inbound message is deduplicated by its provider message id, so a provider retry cannot produce a second reply or a second charge.
Scheduled jobs require a secret. If that secret is missing, the endpoint refuses the request rather than running unauthenticated.
The AI
Replies are checked against your real listings before they are sent. A price or reference that is not in your inventory is regenerated once, and failing that the agent offers to confirm with a human rather than quoting anything.
Your conversations are not used to train models.
Each workspace has a monthly AI budget with a hard stop, so a runaway integration cannot generate unbounded cost or unbounded messages to your customers.
Payments
Card details are handled entirely by Paddle, our merchant of record. HQveyra never sees or stores a card number.
Reporting a vulnerability
with enough detail to reproduce it. We will acknowledge within two business days. Please give us a reasonable window to fix an issue before disclosing it publicly — we will not take legal action against good-faith research.
What we don’t claim
HQveyra is a young product run by a small team. We are not SOC 2 or ISO 27001 certified, we do not offer a contractual uptime SLA on standard plans, and data is stored in our provider’s default region rather than a region of your choosing. If any of those are requirements for you, talk to us before signing up rather than after.