Trust · Agentic Revenue Operating System
Security built for procurement review.
Enterprise buyers need tenancy isolation, provenance, and governed agents — not a black-box outbound bot. Here is how Wavly is designed to be defended in a security questionnaire.
RLS · HMAC webhooks · audit · governance tiers · DPA
Control pillars
Data classes
What lands on the Graph — and how it is handled.
| Class | Handling |
|---|---|
| Workspace & Graph | Accounts, opportunities, product events, agent handoffs — scoped by workspace_id + RLS. |
| CRM / product OAuth | Tokens encrypted at rest; revocable from Settings. Sync runs under your credentials. |
| Payment instruments | Stripe / Razorpay only — Wavly never stores card numbers. |
| Enrichment / contact PII | Budgeted enrichment; review queues before outbound. Not a contact-list product. |
| AI drafts & Memory | Drafts and attributed outcomes stay in-tenant. Provider APIs process on demand; not used to train their foundation models under our contracts. |
Control catalog
01
Authentication
- Supabase Auth for identity sessions
- Workspace membership gates every Graph query
- SSO / SAML on Scale roadmap for enterprise IdP
- API keys rotatable without downtime
02
Transport & host
- TLS for all public endpoints
- App on Vercel; data on managed Supabase Postgres
- Point-in-time backups via platform provider
- Secret rotation playbook for operators
03
Agent control plane
- Autonomy levels: approve-all → draft-for-review → auto-qualified
- Outbound risk behind approval queue by default
- Cross-agent coordination requests typed and auditable
- Customer Revenue DNA™ scoring shows match rationale
04
Operational security
- Rate limits and anomaly signals on ingest
- Queue isolation per tenant for async jobs
- Security event APIs for workspace diagnostics
- Questionnaire turnaround: 2 business days for Scale
Subprocessors (illustrative)
Core infrastructure and billing processors. Full list ships with the DPA package. CRM / product connectors you authorize (e.g. HubSpot, Salesforce, Zoho, Slack, PostHog) sync under your OAuth — they are your systems, not Wavly marketing partners.
Compliance posture
Honest status — we do not claim certifications we have not earned.
| Standard | Status | Notes |
|---|---|---|
| GDPR / EEA | Live | Privacy Policy + DPA template; data-subject requests via privacy@ |
| DPDP Act (India) | Live | Policy aligned; rights requests honored through privacy@ |
| DPA (enterprise) | Available | Self-serve template + countersign request at /security/dpa |
| Data residency | Disclosed | US primary by default; dedicated EU is infra/sales-led |
| SOC 2 Type II | Roadmap | Targeted for Scale procurement — ask hello@ for timeline |
| HIPAA | Out of scope | Wavly is not a covered entity / PHI processor |
Security FAQ
Where does customer and CRM data live?
In your workspace on the Revenue Graph — scoped by tenant RLS. Connected CRM and product integrations sync under your credentials. We do not sell or broker your revenue data.
What is the data residency?
Primary Graph/Auth data for the default Wavly deployment is in the United States. Dedicated EU residency is sales-led infrastructure (separate EU Supabase project) — not a Settings toggle. Region disclosure and DPA: hello@thewavly.com or /security/dpa.
Do agents send without approval?
No for high-risk outbound. Approval tiers keep humans in the loop. Autopilot without governance is not the product.
Can you sign a DPA / answer a security questionnaire?
Yes. Download the DPA template or request a countersigned copy at /security/dpa. For questionnaires, email hello@ — we turn Scale reviews around within 2 business days.
Is the conversion webhook authenticated?
Optional but recommended. Set a webhook signing secret; payloads carry X-Wavly-Signature HMAC-SHA256 verified against the raw body in constant time before database writes.
Procurement packet: DPA · Privacy · Talk to Closer · hello@thewavly.com
Next
Ready for the questionnaire?
Download the DPA, or talk to Closer — governed intake for Scale security review.