Where the authoritative answers live
WHAWIT’s security posture, its full sub-processor list, and its current compliance status are published and kept current at whawit.ai/security. That page is the canonical source; this page summarises it and defers to it on any difference.Compliance status
A SOC 2 Type I readiness programme is in progress, with the audit targeted for Q4 2026 or Q1 2027, covering the Security, Availability and Confidentiality Trust Services Criteria. A Type II observation period would only begin after a Type I report is issued. Stating this plainly is worth more to a procurement team than a badge WHAWIT has not earned. WHAWIT’s infrastructure providers — Google Cloud, MongoDB Atlas, Auth0 and GitHub — each hold their own audited attestations, but those are theirs and are not evidence about WHAWIT. Available to enterprise customers under NDA today: a CSA CAIQ v4 response covering the core control domains, and four written policies — Information Security, Access Control, Incident Response and Change Management. WHAWIT also answers VSAQ and SIG Lite questionnaires. A Data Processing Addendum with EU Standard Contractual Clauses is in preparation and is not yet available. Request the packet at [email protected].What is in place
- Encryption — AES-256 at rest across databases, caches and object storage. TLS 1.2 or higher in transit on every public endpoint, WebSocket connection and internal service call.
- Identity — authentication runs on Auth0 (Okta), with MFA. Access to telemetry, incidents and administration is scoped by organization and by role.
- Tenant isolation — isolation on the shared platform is logical, not physical: every record and telemetry stream carries an explicit organization reference and every query that reads them is scoped to it, with a role check above. It is not a separate database per customer.
- Read-only ingestion — WHAWIT reads your observability providers with read-only credentials. Anything that writes — a fix branch, a pull request, a ticket, an incident synced to an on-call tool — is a separate action you authorise and can see.
- Audit trail — an append-only record of catalogued actions, including every reveal of masked sensitive data: who saw it, which resource, which screen served it, and which data classes had been hidden. It records the categories revealed, never the values.
- Secrets — credentials you connect are held in GCP Secret Manager rather than in the application database, and are deleted when you disconnect the integration.
Data privacy and model training
Your telemetry, incidents, code and configuration are used to provide the service to your organization. Your data is not used to train, fine-tune or improve WHAWIT’s models, and it is not shared with other customers. Analysis runs on Google Cloud Vertex AI, using Gemini and Anthropic Claude served through Vertex AI Model Garden. The complete list of sub-processors that can receive customer data, and what each one receives, is published at whawit.ai/security.Dedicated instances
Dedicated instances are available for pilot and enterprise customers: a deployment with its own database, its own API and worker services, and its own subdomain, with credentials that never cross data planes. Provisioning involves a manual infrastructure step today rather than self-service, so it is arranged with your account team as part of onboarding. Region pinning for a dedicated instance is not available today. If data residency in a specific region is a requirement, raise it early — it is additional infrastructure work, not a configuration switch.Get in touch
Security questions, the security packet, or a vulnerability report all go to [email protected]. WHAWIT acknowledges every report it receives, tells you whether it is being treated as a security incident, and comes back with what was done about it.Trust Center
The authoritative security posture, sub-processor list and compliance status.
Back to architecture
Learn how WHAWIT’s intelligence layer works with your existing observability stack.

