Security & trust
Your customers’ conversations. Guarded like ours.
A communications platform holds the most candid data a business has. This page states, in plain language, how ConnectWiz protects it — the same way the rest of this site states capabilities: what’s real, and where the boundaries are.
The controls
The boring guarantees, stated
Tenant isolation at the database
Every workspace’s rows are separated by row-level security enforced inside PostgreSQL itself — not by remembering to add a WHERE clause. The wall is in the database, where application bugs can’t climb over it.
Access with a spine
Two-factor authentication, role-based access with fifty-five distinct permissions, and audit trails on the actions that matter — who did what is a record, not a memory.
Secrets treated like secrets
Channel tokens, API keys and integration credentials are encrypted at rest, write-only in the panel, sent only in authentication headers and never echoed into logs or error messages.
Signed inbound, everywhere
Every channel webhook is cryptographically verified — HMAC signatures compared in constant time, replay windows, and an idempotency ledger so a captured or repeated delivery dies at the door.
AI with guardrails
The AI answers from your own content and refuses over inventing; its CRM and commerce reads are locked to the identity of the person in the conversation, and writes into external systems stay human.
Consent with evidence
Every consent records what was shown, a version digest, time, source, IP and actor — dimensioned per channel, purpose and category, with Türkiye’s İYS registry integrated for TR traffic.
GDPR & KVKK posture
Data-subject rights are honored on request, processing purposes are documented, and channel-specific realities — like Meta’s processing chain for WhatsApp — are stated in plain language rather than hidden.
Honesty as a control
Every capability page on this site states its real status and limits — the same discipline applies internally: unverified paths ship switched off, and "enabled" means measured.
Responsible disclosure
Found something? Tell us first.
Write to [email protected] with steps to reproduce. We read every report, respond like it matters — because it does — and we won’t take legal action against good-faith research that respects user data and avoids service disruption.
What helps us act fast
The endpoint or surface, reproduction steps, impact as you understand it, and a way to reach you. If the report involves another tenant’s data, stop at proof-of-concept — never at extraction.
Data flow honesty
Where your data goes — and only when you send it there
Connected platforms process what you route to them
Messages on WhatsApp, Messenger or Instagram are processed by Meta; Telegram by Telegram; calls over your NetGSM trunk by NetGSM; campaign email by the ESP you connect. Each integration page on this site states its direction and scope — nothing flows to a platform you haven’t connected.
AI processing, on your terms
AI answers run on the model configuration your workspace chooses — including bring-your-own-key setups where the model relationship and its terms are directly yours. Prompts are grounded in your content; your data is not used to train our models.
Details on data categories, retention and your rights: privacy policy. Questions a page doesn’t answer: ask us directly.
Security questions before you commit?
Bring your checklist — we answer it the way this page is written: plainly, with the boundaries included.