Security

How your data is protected.

Veyra holds the credentials to your business WhatsApp number and every conversation your customers have with you. Here is precisely what we do about that.

Your WhatsApp credentials

Provider tokens are encrypted at rest with AES-256-GCM before they reach the database, under a key held only in the application environment. A database leak on its own does not expose them.

Every message your agent sends goes out through your own provider credentials. There is no shared number and no code path by which one workspace's message could leave from another's.

Access to your workspace

Sessions are signed, expire after 30 days, and can be revoked instantly — changing your password invalidates every existing session everywhere.

Two-factor authentication (TOTP) is available on every account.

Only the workspace owner can change billing, alter agency-wide settings, invite teammates, or delete data. Teammates work the inbox without being able to cancel your subscription or wipe your leads.

Team invites are single-use, expire in seven days, are bound to the address they were sent to, and can be revoked at any time.

Your customers' conversations

Every record is scoped to your workspace and filtered by it on every query. Exports are limited to your own data.

Opt-outs are honoured automatically: a customer who replies STOP stops receiving messages, and is excluded from follow-ups and broadcasts.

You can wipe every lead, conversation, listing and payment request from your own settings, without asking us.

Incoming webhooks

Provider webhooks are authenticated before any work is done — a bearer token for Green API, an HMAC signature for Meta and for Paddle. Requests that fail verification are rejected, not logged and processed.

Every inbound message is deduplicated by its provider message id, so a provider retry cannot produce a second reply or a second charge.

Scheduled jobs require a secret. If that secret is missing, the endpoint refuses the request rather than running unauthenticated.

The AI

Replies are checked against your real listings before they are sent. A price or reference that is not in your inventory is regenerated once, and failing that the agent offers to confirm with a human rather than quoting anything.

Your conversations are not used to train models.

Each workspace has a monthly AI budget with a hard stop, so a runaway integration cannot generate unbounded cost or unbounded messages to your customers.

Payments

Card details are handled entirely by Paddle, our merchant of record. Veyra never sees or stores a card number.

Reporting a vulnerability

Email rizwanchauhdaryn8n@gmail.com with enough detail to reproduce it. We will acknowledge within two business days. Please give us a reasonable window to fix an issue before disclosing it publicly — we will not take legal action against good-faith research.

What we don’t claim

Veyra is a young product run by a small team. We are not SOC 2 or ISO 27001 certified, we do not offer a contractual uptime SLA on standard plans, and data is stored in our provider’s default region rather than a region of your choosing. If any of those are requirements for you, talk to us before signing up rather than after.

← Back to Veyra · System status · Privacy