Security

Kanalia handles customer conversations across WhatsApp, voice and email, so the platform is built with confidentiality, availability and traceability as first-class requirements. This page summarises the controls in place today.

Encryption

Traffic is encrypted in transit with TLS 1.2 or above. Stored data, attachments and backups are encrypted at rest.

Access control

Workspace roles limit who can read conversations, manage automations or change billing. Administrative access is granted on a least-privilege basis.

Audit trail

Enterprise workspaces record administrative and messaging events so operations teams can reconstruct who did what and when.

Segregation

Each workspace's data is logically separated, and access is scoped to the authenticated workspace on every request.

Monitoring

Platform infrastructure and channel connections are monitored continuously, with alerting on availability and error conditions.

Backups and recovery

Databases are backed up regularly with point-in-time recovery, and restore procedures are tested.

Channel providers

WhatsApp traffic is delivered through the official WhatsApp Business Platform. Enterprise customers can connect their own number and Meta business account, keeping channel ownership with the organisation.

Incident response

Suspected incidents are triaged, contained and investigated by the platform team. Where a personal data breach affects a customer, we notify them without undue delay with the information needed for their own regulatory obligations.

Responsible disclosure

If you believe you have found a vulnerability, email sales@kanalia.co with steps to reproduce. Please do not test against live customer data. We acknowledge reports and keep reporters informed until resolution.

Certifications

Formal certification work is in progress. We publish only verified attestations on this page; current customers can request our security questionnaire and sub-processor list at any time.