Trust Center

Security, privacy, and compliance at Wavelength

Wavelength turns calls and notes into process diagrams. Your calls and your diagrams are business data. This page shows how we protect them, what we have done, and what we are working on next.

Public documents
6
Subprocessors
7
Roadmap items done
4 of 10
Data location
United States

Last updated October 7, 2026

Compliance status

We do not hold a SOC 2 report today. Each item shows its real status. We update this page when a status changes.

SOC 2 Type I

Independent audit of control design

Planned

SOC 2 Type II

Independent audit of control operation over time

Planned

CSA STAR Level 1

Public CAIQ self-assessment

Planned

Penetration test

Third-party test of the app

Planned

GDPR DPA

Processor terms with Standard Contractual Clauses

Available

Vendor SOC 2 Type II

Core infrastructure vendors

Yes

Quick summary

The short answers to the questions a security review asks first.

  • We sign a Data Processing Agreement with customers who ask.
  • We publish our subprocessor list and post changes 30 days before they start.
  • You can delete your account and all its data in the app, at any time.
  • We have a vulnerability disclosure process. We reply within 2 business days.
  • All traffic uses TLS. Our database provider encrypts stored data with AES-256.
  • We store your account and your flows in the United States.
  • We do not store your call audio, screen recordings, or photos.
  • Wavelength does not train AI models on your content.
  • Zero data retention is on at our AI provider, Groq.
  • Automated security checks run every week and keep a record of each result.
  • We have a published privacy policy.
  • We do not hold a SOC 2 report yet. See the roadmap.
  • We have not completed a third-party penetration test yet.
  • Self-serve data export is not available yet. Email us and we send your data.

Controls

The measures that protect your data today.

Infrastructure security

4 controls
  • Encryption in transit (TLS) and at rest (AES-256)
  • Data stored in the United States (us-east-1)
  • Daily database backups
  • Hosting and database vendors with SOC 2 Type II reports

Application security

5 controls
  • Row level security is on for every database table
  • Your browser cannot read the database directly
  • Each server function checks a verified sign-in before it reads or writes data
  • Per-account and per-minute limits on AI endpoints
  • Secrets stay in server configuration, not in client code

Data and privacy

4 controls
  • Account isolation: you see only your flows and flows shared with you
  • Delete a flow and we delete its transcript, versions, and share settings
  • Self-serve account deletion in Settings
  • Stripe handles all card data. We never see your full card number

AI and your content

4 controls
  • Audio, video frames, and photos are processed, then not stored
  • Wavelength does not train AI models on your content
  • Zero data retention at Groq for inference requests
  • Full details on the AI and your data page

Vendor management

3 controls
  • Public subprocessor list with location and security reports
  • 30 days notice before a new subprocessor starts
  • Each subprocessor agrees to data protection terms

Incident response

3 controls
  • We tell affected customers within 72 hours after we confirm a breach
  • Security reports go to [email protected]
  • Weekly automated checks for access policies and failed jobs

Documents

Open a public document, or ask us for a document that is on request.

  • Security overviewHow we protect your account and your flows Public View
  • AI and your dataWhat happens to audio, images, and transcripts Public View
  • SubprocessorsCompanies that process customer data Public View
  • Data Processing AgreementGDPR processor terms and annexes Public View
  • Privacy policyWhat we collect and why Public View
  • Terms of serviceThe agreement for using Wavelength Public View
  • Security policiesSummaries of our ten policies. Full text on request. Public View
  • Completed security questionnaireWe answer your questionnaire On request Request
  • CSA CAIQ v4 self-assessmentStandard cloud security questionnaire Planned Not yet
  • Penetration test summaryResults of a third-party test Planned Not yet
  • SOC 2 reportIndependent audit report Planned Not yet

Security policies

Our security program runs on ten written policies. The founder approved version 1.0 of each policy on October 7, 2026. We review each policy at least once each year and after each significant change.

IDPolicyWhat it covers
P1Information Security PolicyThe security program, roles, risk management, audits, and policy exceptions.
P2Access Control PolicyLeast privilege, deny by default, MFA on all admin accounts, and quarterly access reviews.
P3Change Management and Secure Development PolicySecurity rules for each change, build and preview checks, recorded releases, and rollback.
P4Incident Response PlanSeverity levels, response steps, and customer notice within 72 hours after a confirmed breach.
P5Business Continuity and Disaster Recovery PlanRecovery targets for each system, daily backups, and a yearly restore test and exercise.
P6Vendor and Supply Chain PolicySecurity checks before a new vendor, yearly vendor reviews, and the shared responsibility model.
P7Data Management and Privacy PolicyData classes, retention and deletion, data subject requests, and law enforcement requests.
P8Cryptography and Key Management PolicyTLS and AES-256, secrets kept on the server, and yearly key rotation.
P9Logging, Monitoring, and Vulnerability Management PolicyWeekly automated checks, monthly scans, and fix times by severity.
P10Acceptable Use, Endpoint, and Personnel Security PolicyDisk encryption, screen lock, anti-malware, training, and rules for future hires.

These summaries are public. To get the full text of a policy, email [email protected] from your work email.

Subprocessors

The companies that process customer data for Wavelength.

SubprocessorPurposeSecurity reports
SupabaseDatabase and server functionsSOC 2 Type II
Base44 (part of Wix.com)App hosting, sign-in, transactional email, AI summariesSOC 2 Type II, ISO 27001
GroqSpeech-to-text, image reading, diagram generationSOC 2 Type II
StripePayments and billingPCI Level 1, SOC 2 Type II
ResendAccount and product emailSOC 2 Type II
CloudflareDNS and email routingSOC 2, ISO 27001
GoogleWebsite analytics and feedback formsSee Google

See data types and locations on the Subprocessors page.

Compliance roadmap

What is done, and what comes next.

  1. Verified identity on every AI request

    Done

    Requests without a valid sign-in get no data.

  2. Trust pages and DPA published

    Done, October 6, 2026

    Security, AI and data, subprocessors, and DPA pages.

  3. Zero data retention at Groq

    Done, October 6, 2026

    Our AI provider does not keep our request data.

  4. Weekly automated security evidence

    Done, October 7, 2026

    A scheduled job checks database access policies, admin settings, and failed jobs, and records each result.

  5. Isolated production environment

    Planned

    Wavelength data in its own database project.

  6. Written security policies

    Done, October 7, 2026

    Ten policies, including access control, change management, incident response, vendor management, backup and recovery, data retention, and risk assessment.

  7. CSA STAR Level 1

    Planned

    Public self-assessment in the CSA STAR registry.

  8. Third-party penetration test

    Planned

    An independent firm tests the app.

  9. SOC 2 Type I

    Planned

    Audit by an independent CPA firm.

  10. SOC 2 Type II

    Planned

    Audit of controls over a period of months.

Frequently asked questions

Does Wavelength have a SOC 2 report?

No, not today. SOC 2 Type I and Type II are on our roadmap. Our core vendors (Supabase, Base44, Groq, Stripe, and Resend) hold SOC 2 Type II reports.

Does Wavelength store my call audio?

No. We send each audio clip to Groq for speech-to-text. We store the text, not the audio. We store only the clip length, to count your plan's mic minutes.

Does Wavelength train AI models on my data?

No. Wavelength does not train AI models on your audio, images, transcripts, or diagrams. Zero data retention is on for our Groq account.

Where is my data stored?

We store your account and your flows in the United States.

Will you sign a DPA?

Yes. Our DPA covers GDPR and includes the Standard Contractual Clauses for transfers from the EEA, the UK, and Switzerland.

How do I delete my data?

Open Settings in the app and select Delete account. This deletes your flows, transcripts, diagrams, and profile. You can also email [email protected] from your account email. We complete an email request within 30 days.

Will you fill out our security questionnaire?

Yes. Email [email protected] with the questionnaire attached.

Updates

  • October 7, 2026

    We approved our ten security policies and published a summary of each one.

  • October 7, 2026

    We launched this Trust Center. We also started weekly automated security checks with a stored record of each result.

  • October 6, 2026

    We turned on zero data retention at Groq. We updated the AI and Data page to cover screen recordings and photos.

  • October 6, 2026

    We published our Security, AI and Data, Subprocessors, and DPA pages.

Contact

Report a security problem

Email us with the subject "Security". Tell us what you found and how to reproduce it. Please do not access, change, or delete other users' data while you test.

[email protected]

Documents and questionnaires

Email us from your work email. Tell us which documents you need.

[email protected]