Our approach
Whats91 uses technical and organisational measures intended to protect confidentiality, integrity, and availability. Measures are selected according to the service, data, risk, and available technology. This is not a certification or a guarantee that every incident can be prevented.
Safeguard categories
- Access controls and authentication appropriate to administrative and service functions.
- Encrypted network transport where supported by the protocol and connected service.
- Logging, monitoring, and diagnostics for reliability, abuse prevention, and incident investigation.
- Backup, recovery, and change-management practices appropriate to the service component.
- Vendor and contractual controls appropriate to providers processing information for Whats91.
- Processes for vulnerability handling, incident escalation, and service restoration.
Customer responsibilities
- Use unique credentials and available multi-factor authentication, and promptly remove access when roles change.
- Protect API keys, tokens, webhook secrets, connected systems, and devices.
- Grant least-privilege access and regularly review administrators and integrations.
- Validate webhook destinations, restrict logs, and avoid secrets or unnecessary sensitive data in messages.
- Report suspected compromise promptly and cooperate with containment steps.
Incident handling
When Whats91 confirms an incident affecting customer information, it will investigate, contain, remediate, preserve relevant evidence, and provide notices required by law or contract. Timing and detail depend on the facts, investigation security, and legal requirements.
Report a security concern
Send a concise report to support@whats91.com with the subject “Security report”. Include the affected URL or feature, reproduction steps, impact, and safe evidence. Do not access other users’ data, disrupt service, use social engineering, or publish exploitable details before a reasonable investigation opportunity.
Assurance boundary
Security questionnaires, architecture details, test reports, or contract-specific assurances may be available to eligible customers subject to verification, confidentiality, and the purchased service. A website statement does not amend a signed security schedule.
Contact Whats91
For questions, account notices, privacy requests, or legal correspondence, contact us directly. Include enough context to route the request, but do not send passwords, API keys, or one-time codes.