Trust center · Updated April 2026

One URL for your procurement team.

Security controls, compliance posture, uptime history, data residency, Meta Business Partner status, customer proof, and a downloadable DPA. Everything an enterprise buyer needs to close the RFP — on a single page.

Signing entity: Go4whatsup is a product of Inwizards Software Technology — Inwizards Software Technology Pvt. Ltd. (India) for Indian customers, Inwizards Software Technology LLC (UAE) for GCC / EU / UK customers. Both entities apply identical controls.

99.9%Uptime SLA
measured at API gateway
1,500+Businesses
in 40+ countries
4.4/5G2 rating
from verified reviewers
24 hrsBreach notification
tighter than GDPR's 72 hrs
01 — Security

Controls your InfoSec team can verify.

We ship the controls enterprise buyers test on every RFP. Full penetration test report and SOC 2 readiness memo available under NDA.

  • AES-256 encryption at rest live Customer data, message archives, media files. Keys rotated quarterly via AWS KMS.
  • TLS 1.3 in transit live All API, webhook, and dashboard traffic. Qualys SSL Labs A+ grade. HSTS preload.
  • SSO / SAML 2.0 live Okta, Azure AD, Google Workspace, OneLogin. SCIM user provisioning for enterprise plans.
  • Role-based access control (RBAC) live Granular permissions per inbox, broadcast, template, integration. Agent / Manager / Admin / Owner roles plus custom.
  • Audit logs (exportable) live Every action stamped with user, IP, timestamp, target. Exportable as CSV / JSON for your SIEM. 12-month retention.
  • IP allow-listing live Restrict dashboard and API access to specific CIDR ranges. Per-environment (prod / staging) rules.
  • Annual penetration testing live Third-party CREST-certified firm. Most recent report signed 2026-02. Remediation SLA: critical = 72 hrs.
  • Secure SDLC live Mandatory code review, SAST (Semgrep), dependency scanning (Dependabot), secrets scanning pre-commit.
  • 24-hour breach notification SLA live Written notice to your designated security contact within 24 hours of confirmed detection. Tighter than GDPR's 72-hour floor.
02 — Compliance

Certifications & regulatory alignment.

We publish what we have and what's in flight. No “certified by interpretation” wording. If your jurisdiction needs something not on this list, ask sales — we'll say yes or no directly.

GDPR · EU Data Processing Addendum (DPA), SCCs, EU data residency option (Frankfurt), DPO on record. Compliant
AVG · Netherlands GDPR implementation aligned with Autoriteit Persoonsgegevens guidance. Dutch SMB-ready. Compliant
DPDP Act · India India Mumbai region, data fiduciary obligations met, consent records, India-based grievance officer. Compliant
UAE PDPL Dubai region, UAE entity, FTA-registered, aligned with Federal Decree Law 45/2021. Compliant
SOC 2 Type II Controls implemented. Observation window in progress with Schellman. Type II report expected Q4 2026. Type I readiness memo available under NDA today. In progress
ISO 27001:2022 Controls mapped and implemented. External audit booked Q3 2026. Statement of Applicability available under NDA. In progress
Meta Business Partner Official Meta-verified BSP. Direct Cloud API access. Listed on Meta's partner directory. Verified
HIPAA / BAA We do not sign BAAs today. If you're a US healthcare covered entity, we can't be the BSP for PHI-bearing conversations. We'll say so up front. Not available
FedRAMP Not pursued — US federal government isn't a target market. If you're a non-US government entity, we'll discuss case-by-case. Not pursued
03 — Reliability

99.9% uptime SLA with a public status page.

If we miss the SLA in any billing month, you get service credits automatically. No email-your-CSM-for-credit games.

99.97%90-day uptime
at API gateway
Live · updated hourly
<120msP95 API response
time (EU & India)
Rolling 30-day
0Critical P0 incidents
past 90 days
Public history
2xAvailability zones
per region
Active-active

View the live status page →  ·  Subscribe to incident alerts →

04 — Data residency

Pick the region your data lives in.

Message archives, customer records, and media files stay in your chosen region. No cross-region copies. Backup replicas use the same region's availability zones.

  • EU · Frankfurt (AWS eu-central-1) Default for UK, Ireland, Netherlands, Germany, France, Spain, Italy, Belgium, Nordics customers. GDPR & AVG-aligned.
  • India · Mumbai (AWS ap-south-1) Default for India, Sri Lanka, Bangladesh, Nepal customers. DPDP Act-compliant. RBI-acceptable for regulated entities.
  • UAE · Dubai (AWS me-south-1) Default for UAE, Saudi Arabia, Qatar, Kuwait, Oman, Bahrain customers. PDPL-aligned. ADGM/DIFC-friendly.
  • Deletion policy End-user data deletion requests: within 30 days. Admin-initiated full-workspace deletion: primary + backups purged within 90 days. Signed certificate of deletion on request.
05 — Meta partnership

Meta Business Partner — direct Cloud API.

We're on Meta's verified partner directory. Your WhatsApp Business Account connects through official Cloud API — no grey-market on-premise hacks, no shared WABA shortcuts, no rate-limit games.

  • You own the WABA Your WhatsApp Business Account lives in your Meta Business Manager — not ours. If you ever leave, it stays with you. No vendor lock-in.
  • Meta-passthrough conversation pricing Meta's per-conversation fee goes to Meta at cost. We don't mark up Meta's pricing. You see the exact fee in your invoice.
  • Green Tick submission support included Hands-on help preparing your WhatsApp verified-business application. Approval is Meta's call, but we get you past the preventable rejections.
  • Template approval guidance We review every template before you submit, flag the common rejection patterns, and help you rewrite for Meta's policy team.
06 — Customer proof

1,500+ businesses. Real case studies. Real names.

Case studies are on the record with the customer's permission — not anonymised screenshots. You can email the customer's ops lead and ask if they're a real reference.

1,500+Businesses across 40+ countries
4.4/5G2 & Capterra · 120+ verified reviews
10Published case studies with named customers
95%Net revenue retention (last 4 quarters)

Featured case studies: Urban Thread Retail · Al Rawan Travel · MediLife Pharmacy · BrightEdu Schools · Nour Retail · Kitchenly · Saanvi Crafts · Rajasthan Weaves · SkillLab Academy · and more

08 — From the founder

On trust.

Anuj Singh, Founder and CEO of Go4whatsup
“Every enterprise buyer has been burned by a vendor who over-promised on compliance. Our answer: we publish what we have, what's in progress, and what we don't support — on one page, named dates included. If we sign a DPA with your legal team today, the terms match what you read on this page. Not a renegotiation.”
Anuj Singh · Founder & CEO, Go4whatsup

Ready to start the security review?

Share this page with your procurement and InfoSec teams. Our enterprise team responds to RFP questionnaires within one business day — CAIQ, SIG Lite, VSA, and custom formats all accepted.

Book an enterprise demo Send an RFP