Trust · Security · Privacy

Security Note

An overview of the security, privacy, and operational controls implemented by Emovur to protect customer data and ensure the confidentiality, integrity, and availability of our WhatsApp Business API platform.

Version
1.0
Last Updated
14th Aug, 2026
Company
Audentrix Pvt. Ltd.
Product
Emovur WA API
Security is integrated into every stage of design, development & operations
Section 01

Company Overview

Emovur, a product of Audentrix Pvt. Ltd., is a cloud-based WhatsApp Business API platform that enables businesses to communicate with customers at scale over WhatsApp.

The platform provides conversational messaging, shared team inboxes, chatbot automation, AI-assisted customer support, campaign management, workflow automation, and integrations with third-party business applications.

It is designed for businesses of all sizes seeking secure, reliable, and scalable customer communication over WhatsApp.

Head Office
118, Ground Floor, 2nd Cross, 3rd Main Road, Mico Layout, BTM 2nd Stage, Bengaluru, Karnataka 560076, India
Security Contact
Data Protection Officer
Dinesh Kumar · [email protected]
Section 02

Security Philosophy

Security is integrated into every stage of our platform's design, development, deployment, and operations.

Privacy by DesignLeast Privilege AccessDefense in DepthSecure Software DevelopmentContinuous MonitoringData ProtectionOperational ResilienceContinuous Improvement
Section 03

Infrastructure Security

The Emovur platform is hosted on professionally managed cloud infrastructure located in Bengaluru, India.

Infrastructure security controls include
  • Cloud-based firewall protection
  • Web Application Firewall (WAF)
  • Distributed Denial of Service (DDoS) protection
  • Infrastructure monitoring
  • Secure containerized deployments
  • Server hardening
  • HTTPS-only communication
  • TLS 1.2 and TLS 1.3 encryption

Infrastructure is monitored continuously to detect operational issues, abnormal activity, and security events.

Section 04

Data Protection

Customer trust is fundamental to our platform.

We collect only the information required to deliver our services, including account information, contact details, WhatsApp numbers, message content, media, templates, analytics, and operational logs.

Customer information is processed solely for providing, maintaining, securing, and improving the services requested by customers.

Customer data remains stored only for as long as necessary to provide the subscribed services or until deletion is requested, subject to applicable legal or contractual retention obligations.

WhatsApp Data

The platform stores WhatsApp messages and media to provide messaging history, operational continuity, reporting, and customer support capabilities.

Customers may
  • Export supported data
  • Delete conversations
  • Request permanent deletion of stored data

Messages are retained for up to one year unless deleted earlier upon customer request. Message transmission and storage follow Meta's security protocols.

Section 05

Encryption & Key Management

All communications between users, APIs, and platform services are encrypted using HTTPS with TLS 1.2 or TLS 1.3.

Security controls include
  • Database encryption at rest
  • Disk encryption
  • Backup encryption
  • Encrypted network communications

Encryption keys are managed through cloud-based Key Management Services (KMS) with controlled access and periodic key rotation.

Section 06

Identity & Access Management

Platform access is secured through multiple authentication and authorization mechanisms.

Supported authentication methods
  • Username and Password
  • Google Sign-In
  • Multi-Factor Authentication (MFA)
The platform implements
  • Strong password policies
  • Session timeout controls
  • Brute-force protection
  • Role-Based Access Control (RBAC)
  • Administrative access controls
  • Staff access controls
  • Customer-specific permissions

Access to production systems and customer information is restricted to authorized personnel with a legitimate business need.

Section 07

Application Security

Security is embedded throughout the software development lifecycle.

Development practices include
  • Secure Software Development Lifecycle (Secure SDLC)
  • Peer code reviews
  • Automated testing
  • Static code analysis
  • Secret scanning
  • Protected source code branches
  • Secure CI/CD pipelines
  • Controlled production deployment approvals

These controls help identify and remediate security issues prior to production deployment.

Section 08

API Security

The Emovur API implements multiple security controls to protect customer integrations.

These include
  • JWT-based authentication
  • Customer-specific API keys
  • HTTPS-only communication
  • Rate limiting
  • Webhook signature verification
  • Server-side request validation
  • Authentication and authorization enforcement

OAuth authentication and IP allowlisting are not currently supported.

Section 09

Monitoring & Logging

Platform operations are continuously monitored through centralized logging and automated alerting.

Monitoring includes
  • Application logs
  • Security logs
  • Audit logs
  • API logs
  • Login history
  • Failed authentication monitoring
  • Automated alerting for critical operational events

These controls enable rapid detection and response to operational and security incidents.

Section 10

Incident Response

Emovur maintains a documented Incident Response Plan covering the identification, assessment, containment, mitigation, recovery, and post-incident review of security events.

Security incidents are investigated by the Incident Response Team led by Apoorv Chaturvedi, with support from Engineering, Infrastructure, and Product teams.

Our incident management process includes
  • Incident severity classification
  • Continuous monitoring and detection
  • Rapid containment
  • Secure recovery
  • Root Cause Analysis (RCA)
  • Customer communication for material incidents
  • Regulatory notifications where applicable
  • Post-incident review and continuous improvement
Incident Severity Levels
SEV-1
Critical
SEV-2
High
SEV-3
Medium
SEV-4
Low

Customers are notified without undue delay whenever an incident materially impacts customer data, service availability, or platform security.

Section 11

Backup, Disaster Recovery & Business Continuity

Customer data is backed up every 24 hours.

Backups are encrypted and retained for seven days.

Backup restoration is tested monthly to validate recovery procedures.

A documented Disaster Recovery Plan defines procedures for restoring services following major operational disruptions.

Recovery Time Objective (RTO)
4 Hours
Recovery Point Objective (RPO)
15 Minutes
Backup Frequency
Every 24 Hours
Backup Retention
7 Days

Business continuity procedures are maintained to minimize service disruption and ensure operational resilience.

Section 12

Employee Security

Emovur maintains administrative and operational controls to safeguard customer information.

These include
  • Employee background verification
  • Confidentiality agreements (NDAs)
  • Security awareness training
  • Least privilege access
  • Laptop encryption
  • Employee Multi-Factor Authentication
  • Formal offboarding procedures
Section 13

Privacy & Customer Data

Customers retain ownership of all data submitted, generated, or stored through the platform.

Emovur acts as a data processor solely for providing contracted services.

Customers may
  • Request correction of inaccurate information
  • Request deletion of personal data
  • Request permanent deletion of account data
  • Export supported customer data
The platform maintains
  • Privacy Policy
  • Cookie Policy
  • Data Processing Addendum (DPA)
  • Right to Erasure process
  • Data correction procedures

Customer accounts scheduled for closure are permanently removed from production systems within 30 days, subject to applicable legal or contractual retention requirements. Data portability is currently supported for customer data exports as available within the platform.

Section 14

Artificial Intelligence

The platform includes optional AI-powered capabilities.

AI features are optional and enabled only when configured by customers.

Customer data is not used to train third-party AI models.

Optional AI capabilities
  • AI Chatbot
  • AI Inbox Moderator
  • AI Copilot
AI Provider
OpenAI
Section 15

Third-Party Service Providers

Emovur engages carefully selected service providers to operate and deliver the platform.

Provider categories
  • Cloud infrastructure
  • Content delivery and security
  • WhatsApp Business Platform
  • Payment processing
  • Productivity and collaboration
  • AI services
Representative providers
  • Meta
  • Contabo
  • Cloudflare
  • Google
  • Razorpay
  • Zoho
  • Plesk
  • OpenAI

Where applicable, data processing agreements and contractual obligations govern the processing of customer information by third-party service providers.

Section 16

Compliance

Emovur maintains security and privacy controls aligned with recognized industry standards and applicable regulatory requirements.

Aligned
ISO 27001
Certification alignment
Aligned
GDPR
Readiness
Aligned
DPDP, India
Digital Personal Data Protection Act
Aligned
PCI DSS
Scope exclusion (Razorpay processes payments)
Section 17

Service Availability

The platform is designed to provide reliable and resilient service.

Target Availability
99%
SLA
On request
Maintenance Notice
Advance
Maintenance Window
~1 Hour
Section 18

Customer Responsibilities

Customers play an important role in maintaining the security of their accounts and data.

Customers are responsible for
  • Maintaining strong passwords
  • Enabling Multi-Factor Authentication where available
  • Protecting API credentials
  • Managing user permissions appropriately
  • Obtaining required customer consent before sending WhatsApp communications
  • Complying with Meta's WhatsApp Business policies and applicable laws

Questions about our security?

Our team is happy to help with security questionnaires, DPAs, audit reports, and vendor reviews.

© 2026 Audentrix Pvt. Ltd. All Rights Reserved.