Security at Wavelength
Effective October 6, 2026.
Wavelength turns spoken process descriptions into diagrams. Your calls and your diagrams are business data. This page tells you how we protect them.
How we protect your data
- Encryption. All traffic to Wavelength uses HTTPS (TLS). Our database provider encrypts stored data with AES-256.
- Access control. Your browser cannot read our database directly. Every request goes through our server functions. Each function checks who you are from a verified sign-in before it reads or writes data. A request without a valid sign-in gets no data.
- Account isolation. You see only your own flows and the flows that a person shares with you.
- Payments. Stripe processes all payments. We never see or store your full card number.
- Usage limits. Our AI endpoints have per-account and per-minute limits. These limits stop abuse and runaway costs.
- Backups. Our database provider backs up the database every day.
Where your data lives
- We store your account and your flows in the United States.
- Our core infrastructure vendors hold SOC 2 Type II reports. See the full list on our Subprocessors page.
Your call audio and AI
- Read our AI and Data page for the full details.
- In short: we do not store your audio, and we do not train AI models on your content.
Compliance
- We are working toward SOC 2. We do not hold a SOC 2 report today.
- We sign a Data Processing Agreement (DPA) with customers who ask. Our DPA covers GDPR.
- Contact us for a completed security questionnaire.
Report a security problem
- Email [email protected] with the subject "Security".
- Tell us what you found and how to reproduce it.
- We reply within 2 business days.
- Please do not access, change, or delete other users' data while you test.
Incidents
- If a breach affects your personal data, we tell you without undue delay. We tell you within 72 hours after we confirm the breach.