Trust Center
Security, privacy, and compliance at Wavelength
Wavelength turns calls and notes into process diagrams. Your calls and your diagrams are business data. This page shows how we protect them, what we have done, and what we are working on next.
- Public documents
- 6
- Subprocessors
- 7
- Roadmap items done
- 4 of 10
- Data location
- United States
Last updated October 7, 2026
Compliance status
We do not hold a SOC 2 report today. Each item shows its real status. We update this page when a status changes.
SOC 2 Type I
Independent audit of control design
SOC 2 Type II
Independent audit of control operation over time
CSA STAR Level 1
Public CAIQ self-assessment
Penetration test
Third-party test of the app
GDPR DPA
Processor terms with Standard Contractual Clauses
Vendor SOC 2 Type II
Core infrastructure vendors
Quick summary
The short answers to the questions a security review asks first.
- We sign a Data Processing Agreement with customers who ask.
- We publish our subprocessor list and post changes 30 days before they start.
- You can delete your account and all its data in the app, at any time.
- We have a vulnerability disclosure process. We reply within 2 business days.
- All traffic uses TLS. Our database provider encrypts stored data with AES-256.
- We store your account and your flows in the United States.
- We do not store your call audio, screen recordings, or photos.
- Wavelength does not train AI models on your content.
- Zero data retention is on at our AI provider, Groq.
- Automated security checks run every week and keep a record of each result.
- We have a published privacy policy.
- We do not hold a SOC 2 report yet. See the roadmap.
- We have not completed a third-party penetration test yet.
- Self-serve data export is not available yet. Email us and we send your data.
Controls
The measures that protect your data today.
Infrastructure security
4 controls- Encryption in transit (TLS) and at rest (AES-256)
- Data stored in the United States (us-east-1)
- Daily database backups
- Hosting and database vendors with SOC 2 Type II reports
Application security
5 controls- Row level security is on for every database table
- Your browser cannot read the database directly
- Each server function checks a verified sign-in before it reads or writes data
- Per-account and per-minute limits on AI endpoints
- Secrets stay in server configuration, not in client code
Data and privacy
4 controls- Account isolation: you see only your flows and flows shared with you
- Delete a flow and we delete its transcript, versions, and share settings
- Self-serve account deletion in Settings
- Stripe handles all card data. We never see your full card number
AI and your content
4 controls- Audio, video frames, and photos are processed, then not stored
- Wavelength does not train AI models on your content
- Zero data retention at Groq for inference requests
- Full details on the AI and your data page
Vendor management
3 controls- Public subprocessor list with location and security reports
- 30 days notice before a new subprocessor starts
- Each subprocessor agrees to data protection terms
Incident response
3 controls- We tell affected customers within 72 hours after we confirm a breach
- Security reports go to [email protected]
- Weekly automated checks for access policies and failed jobs
Documents
Open a public document, or ask us for a document that is on request.
- Security overviewHow we protect your account and your flows Public View
- AI and your dataWhat happens to audio, images, and transcripts Public View
- SubprocessorsCompanies that process customer data Public View
- Data Processing AgreementGDPR processor terms and annexes Public View
- Privacy policyWhat we collect and why Public View
- Terms of serviceThe agreement for using Wavelength Public View
- Security policiesSummaries of our ten policies. Full text on request. Public View
- Completed security questionnaireWe answer your questionnaire On request Request
- CSA CAIQ v4 self-assessmentStandard cloud security questionnaire Planned Not yet
- Penetration test summaryResults of a third-party test Planned Not yet
- SOC 2 reportIndependent audit report Planned Not yet
Security policies
Our security program runs on ten written policies. The founder approved version 1.0 of each policy on October 7, 2026. We review each policy at least once each year and after each significant change.
| ID | Policy | What it covers |
|---|---|---|
| P1 | Information Security Policy | The security program, roles, risk management, audits, and policy exceptions. |
| P2 | Access Control Policy | Least privilege, deny by default, MFA on all admin accounts, and quarterly access reviews. |
| P3 | Change Management and Secure Development Policy | Security rules for each change, build and preview checks, recorded releases, and rollback. |
| P4 | Incident Response Plan | Severity levels, response steps, and customer notice within 72 hours after a confirmed breach. |
| P5 | Business Continuity and Disaster Recovery Plan | Recovery targets for each system, daily backups, and a yearly restore test and exercise. |
| P6 | Vendor and Supply Chain Policy | Security checks before a new vendor, yearly vendor reviews, and the shared responsibility model. |
| P7 | Data Management and Privacy Policy | Data classes, retention and deletion, data subject requests, and law enforcement requests. |
| P8 | Cryptography and Key Management Policy | TLS and AES-256, secrets kept on the server, and yearly key rotation. |
| P9 | Logging, Monitoring, and Vulnerability Management Policy | Weekly automated checks, monthly scans, and fix times by severity. |
| P10 | Acceptable Use, Endpoint, and Personnel Security Policy | Disk encryption, screen lock, anti-malware, training, and rules for future hires. |
These summaries are public. To get the full text of a policy, email [email protected] from your work email.
Subprocessors
The companies that process customer data for Wavelength.
| Subprocessor | Purpose | Security reports |
|---|---|---|
| Supabase | Database and server functions | SOC 2 Type II |
| Base44 (part of Wix.com) | App hosting, sign-in, transactional email, AI summaries | SOC 2 Type II, ISO 27001 |
| Groq | Speech-to-text, image reading, diagram generation | SOC 2 Type II |
| Stripe | Payments and billing | PCI Level 1, SOC 2 Type II |
| Resend | Account and product email | SOC 2 Type II |
| Cloudflare | DNS and email routing | SOC 2, ISO 27001 |
| Website analytics and feedback forms | See Google |
See data types and locations on the Subprocessors page.
Compliance roadmap
What is done, and what comes next.
-
Verified identity on every AI request
DoneRequests without a valid sign-in get no data.
-
Trust pages and DPA published
Done, October 6, 2026Security, AI and data, subprocessors, and DPA pages.
-
Zero data retention at Groq
Done, October 6, 2026Our AI provider does not keep our request data.
-
Weekly automated security evidence
Done, October 7, 2026A scheduled job checks database access policies, admin settings, and failed jobs, and records each result.
-
Isolated production environment
PlannedWavelength data in its own database project.
-
Written security policies
Done, October 7, 2026Ten policies, including access control, change management, incident response, vendor management, backup and recovery, data retention, and risk assessment.
-
CSA STAR Level 1
PlannedPublic self-assessment in the CSA STAR registry.
-
Third-party penetration test
PlannedAn independent firm tests the app.
-
SOC 2 Type I
PlannedAudit by an independent CPA firm.
-
SOC 2 Type II
PlannedAudit of controls over a period of months.
Frequently asked questions
Does Wavelength have a SOC 2 report?
No, not today. SOC 2 Type I and Type II are on our roadmap. Our core vendors (Supabase, Base44, Groq, Stripe, and Resend) hold SOC 2 Type II reports.
Does Wavelength store my call audio?
No. We send each audio clip to Groq for speech-to-text. We store the text, not the audio. We store only the clip length, to count your plan's mic minutes.
Does Wavelength train AI models on my data?
No. Wavelength does not train AI models on your audio, images, transcripts, or diagrams. Zero data retention is on for our Groq account.
Where is my data stored?
We store your account and your flows in the United States.
Will you sign a DPA?
Yes. Our DPA covers GDPR and includes the Standard Contractual Clauses for transfers from the EEA, the UK, and Switzerland.
How do I delete my data?
Open Settings in the app and select Delete account. This deletes your flows, transcripts, diagrams, and profile. You can also email [email protected] from your account email. We complete an email request within 30 days.
Will you fill out our security questionnaire?
Yes. Email [email protected] with the questionnaire attached.
Updates
- October 7, 2026
We approved our ten security policies and published a summary of each one.
- October 7, 2026
We launched this Trust Center. We also started weekly automated security checks with a stored record of each result.
- October 6, 2026
We turned on zero data retention at Groq. We updated the AI and Data page to cover screen recordings and photos.
- October 6, 2026
We published our Security, AI and Data, Subprocessors, and DPA pages.
Contact
Report a security problem
Email us with the subject "Security". Tell us what you found and how to reproduce it. Please do not access, change, or delete other users' data while you test.
[email protected]Documents and questionnaires
Email us from your work email. Tell us which documents you need.
[email protected]