WhatsApp API Switching providers? Move your WhatsApp number to CommLeap and keep its display name and quality ratingSwitching WhatsApp providers? Migrate to CommLeap
Security & trust

Security & trust, built into every conversation

Customer messages carry account alerts, one-time passwords, health reminders and payment details. CommLeap is a messaging platform designed with that responsibility in mind, with layered controls across infrastructure, access, data and operations.

Our principles

How we think about CPaaS security

Security is a design constraint for everything we build, not a feature we add later. Four principles guide our decisions.

Secure by design

Threats are considered when features are designed, and secure defaults ship with every workspace.

Least privilege

People, services and API keys get only the access they need, for only as long as they need it.

Minimal data

We collect what delivery and support require and let you delete the rest, with retention and masking controls coming soon.

Honest transparency

We explain how each channel handles data, including the parts that are outside our direct control.

Infrastructure & availability

Resilient infrastructure for critical messaging

CommLeap runs on enterprise-grade cloud infrastructure with isolated environments for production, staging and development. The platform is designed to keep time-sensitive traffic such as fraud alerts and one-time passwords moving, even when an individual component, route or carrier has a problem.

  • Redundant services across separate infrastructure zones, designed to avoid single points of failure in core delivery
  • Failover between delivery routes, configured with our team during onboarding; per-message cross-channel fallback Coming soon
  • Encrypted, regularly tested backups with defined restoration procedures
  • Continuous monitoring and alerting, with an on-call engineering rotation
  • Network segmentation, managed firewalls and protection against volumetric attacks
Encryption

Data protected in transit and at rest

Encryption is applied by default. You do not need to enable it or pay extra for it.

In transit

Traffic to the console, REST API and your webhook endpoints is encrypted with modern TLS. Signed (HMAC) webhooks, which will let you verify that events came from CommLeap, are coming soon.

At rest

Message content, contact data, attachments and backups are encrypted at rest using AES-256, with encryption keys managed separately from the data they protect.

Secrets management

Credentials, channel tokens and signing keys live in a dedicated secrets manager with restricted access and rotation, rather than in source code or shared files.

Identity & access

Control exactly who can see and send what

Enterprise messaging touches many teams. CommLeap's access controls let you give each of them what they need, and nothing more.

Single sign-on (SAML) Coming soon

SSO will let you connect your identity provider, enforce SSO for every console user and remove access centrally when people leave.

Multi-factor authentication

Require a second factor for console sign-in, and for sensitive actions such as creating API keys or exporting data.

Role-based access control

Separate permissions for administrators, developers, campaign managers and agents, scoped by brand, number or team.

Least-privilege operations

CommLeap staff access to production is limited by role, approved per need, logged and reviewed.

Scoped API keys

Issue keys per environment and purpose, restrict them to specific channels or actions, and rotate or revoke them at any time.

IP allow-listing

Accept API and console traffic only from the networks you approve, adding a further barrier against leaked credentials.

Audit logs

A clear record of administrative actions Coming soon

Audit logs are coming soon. They will capture who did what, when and from where, from sign-ins and role changes to template edits, key rotations and data exports, and your security team will be able to review them in the console or export them to your SIEM for correlation and long-term retention. Planned capabilities include:

  • User, API key, timestamp and source recorded for each event
  • Filtering by user, action type, workspace or date range
  • Export for investigations, audits and internal reviews
Data governance

Your data, governed by your policies

You decide who can see personal information and where it goes when it leaves the platform, with configurable retention and masking controls coming soon. CommLeap does not use customer data to train shared AI models.

Retention controls Coming soon

Retention controls will let you set retention periods for message content, attachments and logs to match your internal policies and regulatory requirements.

PII masking Coming soon

PII masking will let you mask phone numbers, one-time codes and sensitive fields in logs, the inbox and exports, so teams see only what their role requires.

Deletion and data export

Delete contacts and conversations on request to support data subject rights, and export your data in standard formats whenever you need it.

Regional data hosting

Regional data-hosting options are available for enterprise agreements where supported, to help meet residency and sovereignty requirements.

Channel data flows

How messages travel on each channel

No messaging platform controls the entire path to a customer. Each channel relies on third-party networks with their own policies, so we explain each one plainly for your data protection assessments.

ChannelHow messages travelWhat it means for you
WhatsAppWhatsApp encrypts messages between the customer's app and Meta's Cloud API. Meta, acting as a data processor for the business, decrypts them there and exchanges them with CommLeap over TLS-encrypted connections.Messages are not end-to-end encrypted to CommLeap or your systems. You contract with Meta for WhatsApp Business Platform use, and Meta's terms and policies apply alongside your agreement with CommLeap.
SMSMessages traverse mobile carrier networks and interconnect partners to reach the handset.SMS is not end-to-end encrypted; avoid sending sensitive data beyond what is necessary.
RCS Coming soonMessages are delivered through the RCS Business Messaging ecosystem, which involves platform operators and mobile carriers.Brand verification and carrier policies shape how and where messages are delivered.
VoiceCalls traverse carrier and telephony networks; recordings are stored on CommLeap only when you enable them.Configure recording and disclosures to meet local consent rules.
EmailMessages are delivered to mailbox providers, which store and filter them under their own policies.Encrypted connections to mailbox providers are used wherever the receiving server supports them.
Secure development

Security practices across the software lifecycle

Changes to the platform pass through these safeguards before they reach production.

01

Peer code review

Changes are reviewed by another engineer before merging, with added scrutiny for authentication, access and data handling.

02

Dependency scanning

Third-party libraries and container images are scanned for known vulnerabilities, and fixes are prioritized by severity.

03

Penetration testing

The platform is tested by security specialists who probe our applications and APIs the way an attacker would.

04

Controlled releases

Automated tests, staged rollouts and rollback plans reduce the risk that any single change affects customer traffic.

Incident response

Prepared for the unexpected

We maintain a documented incident response process with defined roles, severity levels and escalation paths. If an incident affects your data, we notify you without undue delay and in line with our contractual and legal obligations, then share what happened and what we changed.

Detect & contain

Monitoring and alerts trigger triage, and our responders act to limit impact.

Notify

Affected customers receive clear, timely updates through their designated contacts.

Review & improve

Root-cause analysis leads to lasting fixes, not just a restored service.

Enterprise messaging compliance

Compliance support for regulated communications

CommLeap is designed to help customers meet their obligations under GDPR, PIPEDA, CASL, TCPA and sector-specific rules in industries such as financial services and healthcare. Consent capture, opt-out handling, quiet hours and sender registration workflows are part of the platform.

Compliance is a shared responsibility: CommLeap secures the platform, while you remain responsible for lawful consent, message content and your own use of each channel. A data processing agreement is available on request.

Frameworks our controls are designed to help you address (not certifications):

GDPRPIPEDACASLTCPADPA on request

Vendor and sub-processor management

Vendors that handle customer data are assessed for security and privacy before we engage them, bound by written data-protection terms and reviewed on an ongoing basis. Our list of sub-processors is available to customers, and we give notice of material changes as set out in our data processing agreement.

Read our privacy policy

Security documentation on request

Our team can share security documentation, complete your security questionnaire and join architecture reviews with your stakeholders. We will publish independent assurance reports here as they become available.

Request security documentation
Responsible disclosure

Found a vulnerability? Tell us.

We value the work of security researchers and welcome reports of potential vulnerabilities in CommLeap services. Send your findings to info@commleap.com with the subject line "Security report" and our security team will review it.

Email the security team

Reporting guidelines

  • Include affected URLs or endpoints, steps to reproduce and potential impact
  • Only test against accounts and data you own or are authorized to use
  • Do not access, modify or retain other customers' data
  • Avoid degrading service, social engineering or physical attacks
  • Give us reasonable time to remediate before public disclosure
FAQ

Security questions, answered

Does CommLeap encrypt customer data?

Yes. Data exchanged with the CommLeap platform, APIs and webhooks is encrypted in transit using TLS, and data stored on the platform is encrypted at rest using AES-256. Credentials and keys are held in a dedicated secrets-management system rather than in application code or configuration files.

Are WhatsApp Business API messages end-to-end encrypted?

Not end-to-end to CommLeap or to your systems. WhatsApp encrypts messages with the Signal protocol between a customer's WhatsApp app and Meta's Cloud API. Meta hosts the Cloud API and, acting as a data processor for the business, decrypts incoming messages (and encrypts outgoing ones) so they can be exchanged with the business and its providers, such as CommLeap, over HTTPS connections protected by TLS. Meta states that the Cloud API may retain message content for up to 30 days, for example to support retransmission. Once messages reach CommLeap, they are protected by the controls described on this page. Meta's processing is governed by its own terms and policies.

Which security certifications does CommLeap hold?

CommLeap does not currently hold independent security certifications or third-party attestation reports. We will publish independent assurance reports here if and when they become available. In the meantime, our team can share security documentation, answer questionnaires and walk your reviewers through our controls. Request security documentation.

Can we sign a data processing agreement?

Yes. A data processing agreement (DPA) is available on request and sets out how CommLeap processes personal data on your behalf, including sub-processors, security measures and assistance with data subject requests.

Where is our data stored?

CommLeap runs on enterprise cloud infrastructure. Regional data-hosting options are available for enterprise agreements where supported. Channel providers such as Meta, mobile carriers and mailbox providers may process messages in their own locations as part of delivery, so we explain each data flow during your review.

Is our data used to train AI models?

No. CommLeap does not use customer data, including message content and contact data, to train shared AI models.

How do we report a security vulnerability?

Email info@commleap.com with the subject line "Security report" with a description of the issue, the affected systems and the steps to reproduce it. Please give us reasonable time to investigate and remediate before any public disclosure.

Bring your security team into the conversation

Share your questionnaire, architecture questions or data-handling requirements. Our team will walk your security, privacy and procurement stakeholders through how CommLeap works.

  • Solution design with a named specialist
  • WhatsApp onboarding and verification support
  • Transparent, volume-based pricing